Courseiva
Question 116 of 464
Network SecurityhardMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A network security administrator is configuring authentication for network devices and wants to use a protocol that supports separate encryption of the entire authentication packet. Which of the following protocols is designed to encrypt the entire authentication packet and is commonly used with AAA services?

⚠ Common exam trap

The N10-009 exam often tests the misconception that RADIUS encrypts the entire packet because it uses a shared secret, but in reality, only the password is encrypted, whereas TACACS+ encrypts the full payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

TACACS+

TACACS+ is the correct answer because it encrypts the entire authentication packet, including the username, password, and all other fields, using a shared secret key. This full-packet encryption is a key differentiator from RADIUS, which only encrypts the password field. TACACS+ is commonly used with AAA services to provide separate authentication, authorization, and accounting processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • RADIUS

    Why it's wrong here

    RADIUS is a widely used AAA protocol, primarily for network access authentication. However, its security model only encrypts the password field within the authentication packet using a shared secret, leaving other critical information like the username, IP address, and service type in cleartext. This selective encryption means that while the password itself is protected, an attacker could still glean significant details about the user and their access request by sniffing the network traffic, compromising overall confidentiality.

    When this WOULD be correct

    When the question asks for a protocol that encrypts only the password and is widely used for network access (e.g., 802.1X) or when the requirement is for a protocol that uses UDP for transport and combines authentication and authorization.

  • TACACS+

    Why this is correct

    TACACS+ is a robust AAA protocol that significantly enhances security by encrypting the entire payload of the authentication packet. Unlike other protocols that might only encrypt specific fields, TACACS+ ensures that all authentication-related data, including usernames, command parameters, and other attributes, remains confidential during transit. This comprehensive encryption provides superior protection against eavesdropping and unauthorized access to sensitive network administration information, making it ideal for securing device management.

  • LDAP

    Why it's wrong here

    LDAP (Lightweight Directory Access Protocol) is fundamentally a protocol for accessing and maintaining distributed directory information services, not an authentication protocol with inherent encryption. While it is commonly used as a backend for authentication by querying user credentials stored in a directory, LDAP itself transmits data, including usernames and passwords, in cleartext by default. To secure LDAP communications and encrypt the entire packet, it must be encapsulated within a secure tunnel using protocols like TLS (Transport Layer Security) or SSL (Secure Sockets Layer), typically referred to as LDAPS.

    When this WOULD be correct

    A question asking which protocol is used for querying and modifying directory services (e.g., Active Directory) to authenticate users or retrieve user attributes, especially when integration with AAA is not the primary focus.

  • Kerberos

    Why it's wrong here

    Kerberos is a network authentication protocol that works on the basis of 'tickets' to allow nodes to prove their identity to one another securely over a non-secure network. While it uses strong symmetric key cryptography to protect these tickets and subsequent communication, it does not encrypt the entire initial authentication packet itself. Instead, it focuses on establishing a secure, mutually authenticated session, where the integrity and confidentiality of subsequent communications are ensured through encrypted service tickets, rather than encrypting the initial credential exchange in its entirety.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

TACACS+Correct answer

Why this is correct

TACACS+ is a robust AAA protocol that significantly enhances security by encrypting the entire payload of the authentication packet. Unlike other protocols that might only encrypt specific fields, TACACS+ ensures that all authentication-related data, including usernames, command parameters, and other attributes, remains confidential during transit. This comprehensive encryption provides superior protection against eavesdropping and unauthorized access to sensitive network administration information, making it ideal for securing device management.

RADIUSWrong answer — click to see why

Why this is wrong here

RADIUS encrypts only the password in the authentication packet, not the entire packet, so it does not meet the requirement for encrypting the entire authentication packet.

★ When this WOULD be the correct answer

When the question asks for a protocol that encrypts only the password and is widely used for network access (e.g., 802.1X) or when the requirement is for a protocol that uses UDP for transport and combines authentication and authorization.

Why candidates choose this

Candidates often associate RADIUS with AAA services and may overlook the specific encryption detail, assuming RADIUS encrypts the entire packet like TACACS+.

LDAPWrong answer — click to see why

Why this is wrong here

LDAP is a directory access protocol, not an authentication protocol designed to encrypt entire authentication packets for AAA services. It does not natively encrypt the entire authentication packet; it typically relies on external encryption like TLS.

★ When this WOULD be the correct answer

A question asking which protocol is used for querying and modifying directory services (e.g., Active Directory) to authenticate users or retrieve user attributes, especially when integration with AAA is not the primary focus.

Why candidates choose this

Candidates may confuse LDAP with authentication protocols because LDAP is often used in authentication processes (e.g., LDAP bind), leading them to think it encrypts the entire authentication packet like TACACS+.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.