Network Access & Device Administration Flashcards

1
Q

Difference between AuthC & AuthZ

A

Authentication verifies User Identity, Authorization determines what user is allowed to do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which protocol is best suited for granular command-level control

A

TACACS+ separates authentication & authorization.

Suitable for authenticating users access to network devices and performing command-level authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which protocol is best suited for authenticating and authorizing a user on the network

A

RADIUS combines authentication and authorization.

Suitable for network access control of users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which protocol can be used for Device Administration AAA

A

TACACS+

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What port is used by TACACS+

A

TCP/49

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What port is used by RADIUS

A

UDP/1812 (AuthC, AuthZ)

UDP/1813 (Acct)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which TACACS messages are sent from AAA client to server

A

START

REQUEST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What needs to match between ISE and NAD to successfully authenticate endpoints

A

Shared secret

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which command allows a switch to send accounting info to ISE

A

radius-server vsa send-accounting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Benefits of TACACS+ over RADIUS

A

Entire payload encrypted

Separates authentication and authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which task types are included in ISE for TACACS+

A

WLC & Shell

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RADIUS responses to Authenticator during Authentication

A

Access-Accept
Access-Reject
Access-Challenge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Global command to turn on 802.1x

A

dot1x system-auth-control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Interface command to turn on 802.1x

A

dot1x pae authenticator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which features must be used on ISE for TACACS+

A

Device Administration License

Device Admin service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly