Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is implementing a network access control (NAC) solution that must authenticate users and devices before granting access to the corporate network. The organization wants to use a protocol that supports both authentication and authorization and can carry attributes such as VLAN assignment and ACLs. The engineer decides to use RADIUS. Which of the following statements about RADIUS is correct?

⚠ Common exam trap

The trap here is assuming RADIUS encrypts all attributes or uses TCP, when it actually only encrypts the password and uses UDP, with EAP requiring encapsulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RADIUS uses UDP ports 1812 for authentication and 1813 for accounting.

RADIUS uses UDP ports 1812 for authentication and 1813 for accounting as assigned by IANA. It encrypts only the password field, not the whole packet, and it requires EAP encapsulation to support EAP methods. Understanding these details is essential for proper NAC implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RADIUS encrypts the entire authentication packet, including attributes, using a shared secret.

    Why it's wrong here

    RADIUS only encrypts the password field in Access-Request packets; other attributes are sent in clear text or protected only by the shared secret's MD5 hash. It does not encrypt the entire packet. This is a common misconception because the shared secret is used for integrity, but not for full encryption.

  • ✗

    RADIUS supports the EAP framework natively without any additional encapsulation.

    Why it's wrong here

    RADIUS does not natively support EAP; EAP messages must be encapsulated within RADIUS attributes (EAP-Message and Message-Authenticator). This is defined in RFC 3579. Without this encapsulation, EAP cannot be carried over RADIUS. So the statement that it supports EAP natively is incorrect.

  • ✓

    RADIUS uses UDP ports 1812 for authentication and 1813 for accounting.

    Why this is correct

    RADIUS traditionally uses UDP ports 1812 (authentication) and 1813 (accounting). These are the official IANA-assigned ports. While some legacy implementations use 1645 and 1646, the standard ports are 1812 and 1813. This is a correct statement about RADIUS.

  • ✗

    RADIUS operates at the application layer and uses TCP for reliable delivery.

    Why it's wrong here

    RADIUS operates at the application layer but uses UDP, not TCP, for transport. UDP is used for efficiency and because RADIUS has its own retransmission mechanism. TCP is not used in standard RADIUS, though RADIUS over TLS (RadSec) uses TCP. The statement that it uses TCP is incorrect.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.