ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security engineer is configuring network device administration for a fleet of edge routers that must support multifactor authentication, command-by-command authorization, and granular accounting logs. The devices already speak AAA protocols and must keep user passwords encrypted end-to-end across the corporate MPLS WAN. Which access control solution best satisfies all of these requirements?
Configure Kerberos authentication on the routers and forward audit logs to a SIEM.
Integrate the routers with the existing RADIUS server using EAP-TLS for multifactor authentication.
Deploy a TACACS+ server cluster and point the routers' AAA settings to it.
Use LDAP over TLS directly on the routers and log commands locally to syslog.
TACACS+ encrypts the entire payload of the authentication packet, supports per-command authorization decisions, and records detailed accounting information, meeting the engineer's encryption, authorization, and logging needs. RADIUS only encrypts the user's password, cannot perform command-by-command authorization, and provides less granular accounting, so it falls short of the stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is TACACS+ and how does it work?
Open an interactive chat with Bash
How does TACACS+ compare to RADIUS?
Open an interactive chat with Bash
Why is encryption important in AAA protocols, and how does TACACS+ ensure safe password handling?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .