Question 116 of 464
N10-009 Network Security Practice Question
A network security administrator is configuring authentication for network devices and wants to use a protocol that supports separate encryption of the entire authentication packet. Which of the following protocols is designed to encrypt the entire authentication packet and is commonly used with AAA services?
⚠ Common exam trap
The N10-009 exam often tests the misconception that RADIUS encrypts the entire packet because it uses a shared secret, but in reality, only the password is encrypted, whereas TACACS+ encrypts the full payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TACACS+
TACACS+ is the correct answer because it encrypts the entire authentication packet, including the username, password, and all other fields, using a shared secret key. This full-packet encryption is a key differentiator from RADIUS, which only encrypts the password field. TACACS+ is commonly used with AAA services to provide separate authentication, authorization, and accounting processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS
Why it's wrong here
RADIUS is a widely used AAA protocol, primarily for network access authentication. However, its security model only encrypts the password field within the authentication packet using a shared secret, leaving other critical information like the username, IP address, and service type in cleartext. This selective encryption means that while the password itself is protected, an attacker could still glean significant details about the user and their access request by sniffing the network traffic, compromising overall confidentiality.
When this WOULD be correct
When the question asks for a protocol that encrypts only the password and is widely used for network access (e.g., 802.1X) or when the requirement is for a protocol that uses UDP for transport and combines authentication and authorization.
- ✓
TACACS+
Why this is correct
TACACS+ is a robust AAA protocol that significantly enhances security by encrypting the entire payload of the authentication packet. Unlike other protocols that might only encrypt specific fields, TACACS+ ensures that all authentication-related data, including usernames, command parameters, and other attributes, remains confidential during transit. This comprehensive encryption provides superior protection against eavesdropping and unauthorized access to sensitive network administration information, making it ideal for securing device management.
- ✗
LDAP
Why it's wrong here
LDAP (Lightweight Directory Access Protocol) is fundamentally a protocol for accessing and maintaining distributed directory information services, not an authentication protocol with inherent encryption. While it is commonly used as a backend for authentication by querying user credentials stored in a directory, LDAP itself transmits data, including usernames and passwords, in cleartext by default. To secure LDAP communications and encrypt the entire packet, it must be encapsulated within a secure tunnel using protocols like TLS (Transport Layer Security) or SSL (Secure Sockets Layer), typically referred to as LDAPS.
When this WOULD be correct
A question asking which protocol is used for querying and modifying directory services (e.g., Active Directory) to authenticate users or retrieve user attributes, especially when integration with AAA is not the primary focus.
- ✗
Kerberos
Why it's wrong here
Kerberos is a network authentication protocol that works on the basis of 'tickets' to allow nodes to prove their identity to one another securely over a non-secure network. While it uses strong symmetric key cryptography to protect these tickets and subsequent communication, it does not encrypt the entire initial authentication packet itself. Instead, it focuses on establishing a secure, mutually authenticated session, where the integrity and confidentiality of subsequent communications are ensured through encrypted service tickets, rather than encrypting the initial credential exchange in its entirety.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓TACACS+Correct answer▾
Why this is correct
TACACS+ is a robust AAA protocol that significantly enhances security by encrypting the entire payload of the authentication packet. Unlike other protocols that might only encrypt specific fields, TACACS+ ensures that all authentication-related data, including usernames, command parameters, and other attributes, remains confidential during transit. This comprehensive encryption provides superior protection against eavesdropping and unauthorized access to sensitive network administration information, making it ideal for securing device management.
✗RADIUSWrong answer — click to see why▾
Why this is wrong here
RADIUS encrypts only the password in the authentication packet, not the entire packet, so it does not meet the requirement for encrypting the entire authentication packet.
★ When this WOULD be the correct answer
When the question asks for a protocol that encrypts only the password and is widely used for network access (e.g., 802.1X) or when the requirement is for a protocol that uses UDP for transport and combines authentication and authorization.
Why candidates choose this
Candidates often associate RADIUS with AAA services and may overlook the specific encryption detail, assuming RADIUS encrypts the entire packet like TACACS+.
✗LDAPWrong answer — click to see why▾
Why this is wrong here
LDAP is a directory access protocol, not an authentication protocol designed to encrypt entire authentication packets for AAA services. It does not natively encrypt the entire authentication packet; it typically relies on external encryption like TLS.
★ When this WOULD be the correct answer
A question asking which protocol is used for querying and modifying directory services (e.g., Active Directory) to authenticate users or retrieve user attributes, especially when integration with AAA is not the primary focus.
Why candidates choose this
Candidates may confuse LDAP with authentication protocols because LDAP is often used in authentication processes (e.g., LDAP bind), leading them to think it encrypts the entire authentication packet like TACACS+.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.