CCNA Network Services and Security Practice Question
In AAA, what does the second A stand for?
⚠ Common exam trap
A frequent exam trap is mistaking the second A in AAA for Accounting or Auditing. Many candidates confuse Authorization with Accounting because both start with 'A' and relate to user management. However, Authorization specifically controls what an authenticated user is allowed to do, while Accounting tracks user activities for logging and auditing purposes. Selecting Accounting as the second A overlooks the sequential process where permissions are granted immediately after authentication, before any activity is logged. This confusion can lead to incorrect answers and misunderstanding of Cisco AAA implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
AAA stands for Authentication, Authorization, and Accounting. Authorization determines what an authenticated user is allowed to do.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application
Why it's wrong here
The term 'Application' is not part of the AAA framework; AAA strictly refers to Authentication, Authorization, and Accounting. While network services or software applications may invoke AAA protocols like RADIUS or TACACS+, the second 'A' in the acronym is never 'Application.' Choosing this would confuse the protocol framework with the software layer that relies on it, which is why it is incorrect.
When this WOULD be correct
If the exam question were to ask about the components of a software architecture model or a specific application framework, where the focus is on the roles of different components, 'Application' could be a correct answer in that context.
- ✗
Accounting
Why it's wrong here
In AAA, Accounting is actually the third 'A,' not the second. Accounting tracks and measures user activity, resource consumption, and session statistics for auditing, billing, or capacity planning purposes. Since the correct sequence is Authentication → Authorization → Accounting, the second step is Authorization, making Accounting an incorrect choice for the second 'A'.
When this WOULD be correct
If the exam question asked about the components of a billing or usage tracking system in network management, where 'Accounting' refers to the process of recording user activities and resource usage, then option B would be the correct answer.
- ✓
Authorization
Why this is correct
In the AAA security model, the second 'A' stands for Authorization, which is the process of determining what actions or resources an authenticated user is permitted to access. After a user proves their identity via authentication, authorization enforces policies such as permit/deny rules, often based on roles or attributes, and is a distinct step from authentication and accounting. For example, in Cisco ISE, authorization may assign a VLAN or ACL after authentication succeeds.
- ✗
Auditing
Why it's wrong here
Although 'Auditing' is operationally related to security monitoring, it is not a term in the AAA acronym. The AAA model uses 'Accounting' to cover the collection of log and usage data, whereas auditing is a broader review process that may analyze accounting records after the fact. Therefore, Auditing is not the second 'A,' as the framework specifically names Authentication, Authorization, and Accounting.
When this WOULD be correct
If the question were framed as 'Which of the following is a component of security monitoring that involves reviewing user activities and access logs?', then 'Auditing' would be the correct answer, as it directly pertains to the process of examining and verifying user actions.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓AuthorizationCorrect answer▾
Why this is correct
In the AAA security model, the second 'A' stands for Authorization, which is the process of determining what actions or resources an authenticated user is permitted to access. After a user proves their identity via authentication, authorization enforces policies such as permit/deny rules, often based on roles or attributes, and is a distinct step from authentication and accounting. For example, in Cisco ISE, authorization may assign a VLAN or ACL after authentication succeeds.
✗ApplicationWrong answer — click to see why▾
Why this is wrong here
Application is not part of the AAA acronym. AAA stands for Authentication, Authorization, and Accounting. Application is unrelated to this security framework.
★ When this WOULD be the correct answer
If the exam question were to ask about the components of a software architecture model or a specific application framework, where the focus is on the roles of different components, 'Application' could be a correct answer in that context.
Why candidates choose this
The word 'Application' might be tempting because it starts with 'A' and is a common term in networking (e.g., application layer). However, it has no place in the AAA model.
✗AccountingWrong answer — click to see why▾
Why this is wrong here
Accounting is the third 'A' in AAA, not the second. Accounting involves tracking user activities and resource usage for billing or auditing purposes. The second A is Authorization.
★ When this WOULD be the correct answer
If the exam question asked about the components of a billing or usage tracking system in network management, where 'Accounting' refers to the process of recording user activities and resource usage, then option B would be the correct answer.
Why candidates choose this
Students often memorize the three A's but may forget the order. Since Accounting is a well-known term in AAA, it is easy to mistakenly place it as the second A instead of the third.
✗AuditingWrong answer — click to see why▾
Why this is wrong here
Auditing is not a standard component of the AAA framework. The three A's are Authentication, Authorization, and Accounting. Auditing may be considered part of Accounting or a separate security function, but it is not the second A.
★ When this WOULD be the correct answer
If the question were framed as 'Which of the following is a component of security monitoring that involves reviewing user activities and access logs?', then 'Auditing' would be the correct answer, as it directly pertains to the process of examining and verifying user actions.
Why candidates choose this
Students might confuse 'Auditing' with 'Accounting' because both involve logging and monitoring user activities. The similarity in sound and function can lead to the mistaken belief that Auditing is the second A.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.