Exam 200-301 All QuestionsBrowse all questions from this exam
Question 294

Which protocol must be implemented to support separate authorization and authentication solutions for wireless APs?

    Correct Answer: B

    To support separate authorization and authentication solutions for wireless access points, TACACS+ is the most suitable protocol. TACACS+ provides the ability to split the authentication, authorization, and accounting (AAA) functions, enabling clear separation between authentication and authorization processes. This architecture allows the flexibility to use different authentication methods while still managing authorization independently.

Discussion
RonildOption: B

Correct: B Authentication and Authorization RADIUS combines authentication and authorization. The access-accept packets sent by the RADIUS server to the client contain authorization information. This makes it difficult to decouple authentication and authorization. TACACS+ uses the AAA architecture, which separates AAA. This allows separate authentication solutions that can still use TACACS+ for authorization and accounting. For example, with TACACS+, it is possible to use Kerberos authentication and TACACS+ authorization and accounting. After a NAS authenticates on a Kerberos server, it requests authorization information from a TACACS+ server without having to re-authenticate. The NAS informs the TACACS+ server that it has successfully authenticated on a Kerberos server, and the server then provides authorization information. Source: https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html

Isuzu

but the question state "SEPARATE authorization and authentication solutions...."

NURANCY9Option: A

Correct Answer: A The key word in the question is "solution." Separate Authorization and Authentication Solutions..... Indeed is the RADIUS that can solve the problem of separation by combining the two. TACACS+ allows seperation of AAA

Lse

You have opened my brain to re-think, however question says <<to support separate authorization and authentication solutions>>. RADIUS dos the job but TACACS+ is even better??? RADIUS does not strictly separate authentication and authorization into distinct processes like TACACS+, it does provide both authentication and authorization functionalities within the same protocol.

rozekjablkowyOption: B

Correct: B Authentication and Authorization RADIUS combines authentication and authorization.

adrianspaOption: B

TACACS+ uses the AAA architecture, which separates AAA

tumajayOption: C

Why do i think 802.1X is the answer? Tacacs is not really used on wireless network solutions. And if you use 802.1X for authentication on the wireless network, you have separated the solution of authentication and authorization while making Radius do the backend authorization. On wireless networks, 802.1X and radius are usually used together to provide authentication and authorization .

eb63e5aOption: B

correct Answer is B

SeMo0o0oOption: B

it´s B

923ffda

what a tricky question

Da_CostaOption: A

The question is tricky it says to support separate....

DarkarOption: B

it is TACACS+

Andu93Option: B

tacas +

NURANCY9Option: A

Correct Answer: A The key word in the question is "solution." Separate Authorization and Authentication Solutions..... Indeed is the RADIUS that can solve the problem of separation by combining the two. TACACS+ allows seperation of AAA

Junior_NetworkOption: B

it must b TACACS+

kylepttOption: B

Separate is the key word here

wakaishOption: A

RADIUS (Remote Authentication Dial-In User Service) is commonly used for both authentication and authorization in networking environments. It allows for separate authentication (verifying the identity of the user or device) and authorization (determining what the authenticated user or device is allowed to access) processes. This is important in scenarios like wireless networks where you want to control who can access the network and what resources they can access.

mayra20Option: A

A is correct

BAT47Option: B

correct answer: B