Courseiva
hardMultiple Select

ISC2 CC Practice Question: A security administrator is reviewing the…

A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)

⚠ Common exam trap

ISC2 often tests that candidates confuse 'Identification' with 'Authentication' or think 'Auditing' is a core AAA component instead of 'Accounting', leading them to select B or E incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization

Authorization (A) is a core AAA component because it determines what resources and actions an authenticated identity is permitted to access, typically enforced through policies, roles, or permissions. Authentication (D) is also a core AAA component because it verifies the identity of a subject, usually via credentials such as passwords, tokens, or certificates, before access is granted. Together with Accounting, these form the AAA framework. Identification (B) is a prerequisite step where a subject claims an identity, but it is not one of the three AAA components. Non-repudiation (C) is a security property often supported by auditing and digital signatures, not a core AAA component. Auditing (E) is related to accounting/logging but is not itself one of the AAA framework components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authorization

    Why this is correct

    Authorization is a core AAA component: it determines what an authenticated subject may access, by evaluating permissions against requested resources. Alongside authentication and accounting, it forms the framework's three pillars, satisfying the stem's requirement for a core AAA element.

  • ✗

    Identification

    Why it's wrong here

    Identification is the claim of an identity, but AAA's core components are authentication, authorisation and accounting; identification precedes authentication rather than forming one of the three. It is tempting because identification is a prerequisite step, yet the framework itself comprises the three A processes.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation is a security property delivered by digital signatures and logging, not an AAA component; the framework comprises authentication, authorisation and accounting. It is tempting because accounting evidence underpins non-repudiation, so non-repudiation would be the correct answer if the question asked which property signatures provide.

  • ✓

    Authentication

    Why this is correct

    Authentication verifies a subject's claimed identity before any access is granted, forming the first pillar of AAA. In this scenario it satisfies the stem's requirement for a core AAA component, distinct from Authorisation (what the identity may do) and Accounting (logging that activity).

  • ✗

    Auditing

    Why it's wrong here

    Auditing records activity after the fact; it is not one of the three AAA functions, which are authentication, authorisation and accounting. It is tempting because logging and audit trails support accountability, and auditing would be the right control when the requirement is to prove who accessed a resource and when.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.