exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 232 discussion

Actual exam question from Cisco's 200-301
Question #: 232
Topic #: 1
[All 200-301 Questions]

What is the difference between RADIUS and TACACS+?

  • A. RADIUS logs all commands that are entered by the administrator, but TACACS+ logs only start, stop, and interim commands.
  • B. TACACS+ separates authentication and authorization, and RADIUS merges them.
  • C. TACACS+ encrypts only password information, and RADIUS encrypts the entire payload.
  • D. RADIUS is most appropriate for dial authentication, but TACACS+ can be used for multiple types of authentication.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Shamwedge
Highly Voted 3 years, 2 months ago
Selected Answer: B
TACAS+ A-Authentictaion | A-Authorization (Both A's are sperated by a C) = TACAS+ seperates Authentication and Authorization.
upvoted 50 times
MarioE
2 years, 1 month ago
Haha Nice! Good way to remember this ;-)
upvoted 2 times
...
dipanjana1990
3 years ago
hehe "separated by C" now m never gonna forget this.
upvoted 9 times
...
xbololi
1 year, 10 months ago
Thank you <3
upvoted 1 times
...
...
[Removed]
Highly Voted 4 years, 9 months ago
B is correct answer. https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html
upvoted 8 times
...
bymrdas
Most Recent 10 months, 1 week ago
Selected Answer: B
B is correct.
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
ricky1802
1 year, 3 months ago
Selected Answer: B
RADIUS uses UDP while TACACS+ uses TCP. RADIUS encrypts only the password in the access-request packet, from the client to the server. The remainder of the packet is unencrypted. Other information, such as username, authorized services, and accounting, can be captured by a third party. TACACS+ encrypts the entire body of the packet but leaves a standard TACACS+ header. RADIUS combines authentication and authorization. TACACS+ uses the AAA architecture, which separates AAA.
upvoted 3 times
...
Ciscoman021
2 years, 1 month ago
Selected Answer: B
the correct answer is option B: TACACS+ separates authentication and authorization, while RADIUS combines them. Option A is incorrect because neither RADIUS nor TACACS+ is designed to log commands entered by administrators. Option C is incorrect because both RADIUS and TACACS+ can encrypt sensitive information. Option D is incorrect because both RADIUS and TACACS+ can be used for various types of authentication, including dial-up, wireless, and VPN.
upvoted 4 times
...
guisam
2 years, 4 months ago
https://www.geeksforgeeks.org/difference-between-tacacs-and-radius/
upvoted 1 times
...
miki1001
2 years, 9 months ago
Selected Answer: C
TACACS+ encrypts only password information, and RADIUS encrypts the entire payload.
upvoted 3 times
Customexit
2 years, 6 months ago
TACACS is more secure. Encrypts the whole packet including username, password, and attributes. RADIUS only encrypts the password.
upvoted 4 times
...
mzu_sk8
2 years, 5 months ago
31 days before the exam, page 179, RADIUS encrypts only the password , TACACS the entire packet
upvoted 3 times
...
...
miki1001
2 years, 9 months ago
TACACS (Terminal Access Controller Access Control System) is a security protocol that provides centralized validation of users who are attempting to gain access to a router or NAS. TACACS+ provides separate authentication, authorization and accounting services RADIUS combines authenticaiton and authorization into a single function; TACACS+ allows these services to be split between different servers. TACACS+ encrypts only password information, and RADIUS encrypts the entire payload.
upvoted 1 times
RougePotatoe
2 years, 6 months ago
You got tacacs and radius encryption backwards
upvoted 1 times
...
...
schleef
3 years, 5 months ago
"RADIUS combines authentication and authorization. The access-accept packets sent by the RADIUS server to the client contain authorization information. This makes it difficult to decouple authentication and authorization. TACACS+ uses the AAA architecture, which separates AAA. This allows separate authentication solutions that can still use TACACS+ for authorization and accounting. For example, with TACACS+, it is possible to use Kerberos authentication and TACACS+ authorization and accounting." Source: https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html
upvoted 5 times
xtraMiles
9 months, 1 week ago
Good info!
upvoted 1 times
...
...
Benjamin8189
3 years, 6 months ago
-TACACS+ provides for separate and modular authentication, authorization, and accounting facilities -In the Cisco implementation, RADIUS clients run on Cisco routers and send authentication requests to a central RADIUS server that contains all user authentication and network service access information
upvoted 1 times
...
ZUMY
4 years ago
B is correct https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago