Courseiva
Question 435 of 464
Network OperationsmediumMultiple ChoiceObjective-mapped

N10-009 Network Operations Practice Question

A network administrator needs to implement a solution that allows for centralized management of user authentication, authorization, and accounting for network device access. The solution must support encryption of the entire authentication process. Which protocol should be selected?

⚠ Common exam trap

The N10-009 exam often tests the misconception that RADIUS encrypts all traffic because it uses a shared secret, but the trap is that RADIUS only encrypts the password, not the entire packet, whereas TACACS+ encrypts the full authentication payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

TACACS+

TACACS+ is the correct choice because it separates authentication, authorization, and accounting (AAA) into distinct processes and encrypts the entire authentication payload, including the username, password, and all other traffic between the client and the server. This full-packet encryption ensures that credentials and session details are protected during transit, meeting the requirement for centralized management with encrypted authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • TACACS+

    Why this is correct

    TACACS+ is the optimal choice for centralized management of network devices because it provides robust Authentication, Authorization, and Accounting (AAA) services. It encrypts the entire authentication packet, including username, password, and command authorization details, ensuring maximum security for administrative sessions. This comprehensive encryption, combined with its ability to separate AAA functions, makes it ideal for managing routers, switches, and firewalls securely over TCP.

  • RADIUS

    Why it's wrong here

    RADIUS is primarily designed for network access control (e.g., VPN, 802.1X) and, while it offers AAA, it only encrypts the password field within the authentication packet. The username and other attributes are transmitted in clear text, which is a significant security vulnerability for sensitive network device administration. Furthermore, RADIUS combines authentication and authorization into a single process, making it less flexible for granular command control compared to TACACS+.

    When this WOULD be correct

    A network administrator needs a protocol for centralized authentication, authorization, and accounting for network access (e.g., VPN or wireless) that supports encryption of the password only, and the solution must be an open standard.

  • LDAP

    Why it's wrong here

    LDAP (Lightweight Directory Access Protocol) is fundamentally a protocol for accessing and maintaining distributed directory information services, not a full-fledged AAA protocol for network devices. While it can be used as an authentication source to verify user identities, it does not inherently provide authorization for specific commands or comprehensive accounting records for administrative actions. Therefore, it lacks the complete suite of features required for secure, centralized management of network infrastructure.

    When this WOULD be correct

    A question asks: 'Which protocol is used to centralize user authentication and authorization for accessing directory services, such as verifying user credentials against an Active Directory database?' In that context, LDAP would be the correct answer.

  • Kerberos

    Why it's wrong here

    Kerberos is a ticket-based authentication system primarily used for single sign-on within Windows Active Directory domains, designed to authenticate users and services securely across untrusted networks. It is not typically implemented as a direct AAA protocol for managing diverse network devices like routers and switches. Kerberos lacks native accounting capabilities for device administration and does not offer the granular command authorization features essential for centralized network device management.

    When this WOULD be correct

    A question asks: 'Which protocol provides secure authentication for users accessing services in a Windows domain environment, using a ticket-granting system and supporting mutual authentication?' In that context, Kerberos is the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

TACACS+Correct answer

Why this is correct

TACACS+ is the optimal choice for centralized management of network devices because it provides robust Authentication, Authorization, and Accounting (AAA) services. It encrypts the entire authentication packet, including username, password, and command authorization details, ensuring maximum security for administrative sessions. This comprehensive encryption, combined with its ability to separate AAA functions, makes it ideal for managing routers, switches, and firewalls securely over TCP.

RADIUSWrong answer — click to see why

Why this is wrong here

RADIUS encrypts only the password in the authentication process, not the entire session, whereas the question requires encryption of the entire authentication process.

★ When this WOULD be the correct answer

A network administrator needs a protocol for centralized authentication, authorization, and accounting for network access (e.g., VPN or wireless) that supports encryption of the password only, and the solution must be an open standard.

Why candidates choose this

Candidates often confuse RADIUS with TACACS+ because both provide AAA services, but they may overlook the encryption scope difference.

LDAPWrong answer — click to see why

Why this is wrong here

LDAP is primarily a directory access protocol for querying and modifying directory services, not a full AAA protocol. It does not natively support accounting or encrypt the entire authentication process; encryption is typically added via LDAPS, but it lacks the integrated AAA framework required for network device access management.

★ When this WOULD be the correct answer

A question asks: 'Which protocol is used to centralize user authentication and authorization for accessing directory services, such as verifying user credentials against an Active Directory database?' In that context, LDAP would be the correct answer.

Why candidates choose this

Candidates may confuse LDAP's role in authentication (e.g., binding to a directory) with a complete AAA solution, or they might think LDAP with SSL/TLS provides the required encryption and centralized management.

KerberosWrong answer — click to see why

Why this is wrong here

Kerberos is a ticket-based authentication protocol that does not natively provide centralized accounting for network device access, nor does it encrypt the entire authentication process (only the ticket exchange is encrypted). It is designed for single sign-on in a domain environment, not for AAA of network devices.

★ When this WOULD be the correct answer

A question asks: 'Which protocol provides secure authentication for users accessing services in a Windows domain environment, using a ticket-granting system and supporting mutual authentication?' In that context, Kerberos is the correct answer.

Why candidates choose this

Candidates may confuse Kerberos's strong encryption and authentication capabilities with the AAA requirements, overlooking that it lacks built-in authorization and accounting features for network device management.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.