ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An organization with hundreds of multi-vendor routers, switches, and wireless controllers wants to replace locally configured administrator accounts with a centralized AAA solution that can integrate with Active Directory. Security policy requires per-command authorization, full-packet encryption between each device and the authentication server, and detailed accounting logs. Which protocol should the network team configure on the infrastructure devices to meet these requirements?
TACACS+ was designed by Cisco (and later standardized) specifically for device administration. It separates authentication, authorization, and accounting, enabling per-command authorization and granular auditing. Unlike RADIUS, TACACS+ encrypts the entire payload-not just user passwords-meeting the full-encryption requirement. IEEE 802.1X provides port-based network access control for endpoints rather than device administration, and Kerberos is primarily an operating-system authentication protocol that most network devices do not support for CLI access. Therefore, TACACS+ is the only option that satisfies all stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is TACACS+ and how does it differ from RADIUS?
Open an interactive chat with Bash
Why does TACACS+ encrypt the entire payload instead of just passwords?
Open an interactive chat with Bash
How does TACACS+ provide per-command authorization?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .