mediumMultiple Select
CCNP Practice Question: Which two statements about AAA authorization and…
Which two statements about AAA authorization and accounting are true? (Choose two.)
⚠ Common exam trap
The trap here is conflating the three A's — candidates often assume authorization includes encryption or that accounting performs authentication, when each function is strictly separate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization determines what commands a user is allowed to execute after authentication.
Option A is correct because AAA authorization, which occurs after authentication succeeds, defines the privileges and specific commands a user is permitted to execute on the device, typically enforced via per-user or per-group attributes returned by the AAA server (e.g., TACACS+ or RADIUS attributes). Option D is correct because AAA accounting logs user activity—such as start/stop times, commands issued, and bytes transferred—into accounting records that support auditing, billing, and security monitoring. Option B is not correct because encryption of traffic between client and server is a function of the AAA protocol/transport (e.g., TACACS+ encrypts the entire payload, RADIUS encrypts only the password), not of authorization. Option C is not correct because accounting does not authenticate users; authentication verifies identity, while accounting records activity. Option E is not correct because authorization can be based on many factors, including user identity, group membership, time-of-day, and per-command attributes, not solely the source IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization determines what commands a user is allowed to execute after authentication.
Why this is correct
Authorization defines the privileges granted to an authenticated identity, so it directly governs which commands a user may execute on the device. This satisfies the stem's requirement by separating authorisation from authentication, which only verifies identity, and from accounting, which logs activity.
- ✗
Authorization ensures that all traffic between the client and server is encrypted.
Why it's wrong here
Authorisation determines which services or commands an authenticated user may access; it does not encrypt traffic. Encryption between client and AAA server is provided by protocols such as RADIUS over TLS or IPsec. Authorisation would be correct where the requirement is per-user service entitlement.
- ✗
Accounting is used to authenticate users based on their previous login history.
Why it's wrong here
Accounting records session activity — start, stop, commands, bytes — for auditing and billing; it does not authenticate anyone. Authentication verifies credentials, and authorisation determines permitted actions. Accounting would be the correct answer where the requirement is usage logging or chargeback reporting.
- ✓
Accounting provides a record of user activities for auditing or billing purposes.
Why this is correct
Accounting logs each session's start, stop, commands and bytes, producing the audit trail and usage data that billing and forensic review require. This satisfies the stem's auditing-or-billing constraint, which authorisation alone cannot meet since authorisation only permits or denies access.
- ✗
Authorization can only be based on the source IP address of the user.
Why it's wrong here
Authorisation policies can match many attributes — group membership, time of day, device posture, service type — not solely source IP. Source IP is one possible condition among many. This option would hold only if the policy engine were restricted to Layer 3 address matching alone.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.