hardMultiple Select
ISC2 CC Practice Question: A security administrator is reviewing the…
A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)
⚠ Common exam trap
ISC2 often tests that candidates confuse 'Identification' with 'Authentication' or think 'Auditing' is a core AAA component instead of 'Accounting', leading them to select B or E incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
Authorization (A) is a core AAA component because it determines what resources and actions an authenticated identity is permitted to access, typically enforced through policies, roles, or permissions. Authentication (D) is also a core AAA component because it verifies the identity of a subject, usually via credentials such as passwords, tokens, or certificates, before access is granted. Together with Accounting, these form the AAA framework. Identification (B) is a prerequisite step where a subject claims an identity, but it is not one of the three AAA components. Non-repudiation (C) is a security property often supported by auditing and digital signatures, not a core AAA component. Auditing (E) is related to accounting/logging but is not itself one of the AAA framework components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization
Why this is correct
Authorization is a core AAA component: it determines what an authenticated subject may access, by evaluating permissions against requested resources. Alongside authentication and accounting, it forms the framework's three pillars, satisfying the stem's requirement for a core AAA element.
- ✗
Identification
Why it's wrong here
Identification is the claim of an identity, but AAA's core components are authentication, authorisation and accounting; identification precedes authentication rather than forming one of the three. It is tempting because identification is a prerequisite step, yet the framework itself comprises the three A processes.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is a security property delivered by digital signatures and logging, not an AAA component; the framework comprises authentication, authorisation and accounting. It is tempting because accounting evidence underpins non-repudiation, so non-repudiation would be the correct answer if the question asked which property signatures provide.
- ✓
Authentication
Why this is correct
Authentication verifies a subject's claimed identity before any access is granted, forming the first pillar of AAA. In this scenario it satisfies the stem's requirement for a core AAA component, distinct from Authorisation (what the identity may do) and Accounting (logging that activity).
- ✗
Auditing
Why it's wrong here
Auditing records activity after the fact; it is not one of the three AAA functions, which are authentication, authorisation and accounting. It is tempting because logging and audit trails support accountability, and auditing would be the right control when the requirement is to prove who accessed a resource and when.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.