hardMultiple Select
ISC2 CC Practice Question: Which THREE components are part of the AAA…
Which THREE components are part of the AAA framework?
⚠ Common exam trap
ISC2 often tests the distinction between 'Accounting' and 'Auditing' — candidates confuse the two because both involve logs, but Accounting is the collection of data (e.g., start/stop records), while Auditing is the analysis of that data, which is not part of the AAA framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication
The AAA framework consists of Authentication, Authorization, and Accounting. Option A (Authentication) is correct because it verifies a user's or device's identity, typically via credentials such as passwords, certificates, or tokens, before granting access. Option E (Authorization) is correct because it determines what an authenticated identity is permitted to do, such as which resources, commands, or services it may access. Option D (Accounting) is correct because it tracks and logs resource usage and activity, often recording session start/stop times, bytes transferred, and commands executed for billing, auditing, or security analysis. Option B (Accountability) is not one of the three AAA components, though it is a related security goal supported by accounting and auditing. Option C (Auditing) is also not part of the AAA acronym; auditing is a separate process that reviews logs and controls, often using the records produced by accounting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authentication
Why this is correct
Authentication is the first component of the AAA framework: it verifies a subject's claimed identity, typically via credentials, certificates or tokens, before any access decision is made. Authorisation and accounting depend on this verified identity.
- ✗
Accountability
Why it's wrong here
Accountability is a security principle, not an AAA component; the framework comprises authentication, authorisation and accounting. It is tempting because accountability is often discussed alongside auditing, but it belongs to governance and non-repudiation, whereas AAA's third element is accounting, which logs resource usage for billing and audit trails.
- ✗
Auditing
Why it's wrong here
Auditing records activity for accountability but is not one of the three AAA framework components, which are authentication, authorisation and accounting. It is tempting because auditing is closely associated with accounting and logging, and it would be correct when describing governance or compliance controls rather than the AAA framework itself.
- ✓
Accounting
Why this is correct
Accounting is the third AAA component: it logs and tracks what an authenticated, authorised subject actually did, recording resource usage and activity for auditing, billing and forensic purposes. It completes the framework alongside authentication and authorisation.
- ✓
Authorization
Why this is correct
Authorization is the AAA component that determines what an authenticated identity may access, enforcing permissions and privileges after identity verification. It satisfies the framework's requirement to control resource access, complementing authentication (who you are) and accounting (what you did).
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.