mediumMultiple Choice
CISSP Practice Question: A company implements a centralized authentication…
A company implements a centralized authentication system using RADIUS for network devices. The security team notices that after a user's password is changed in Active Directory, the user can still authenticate to network devices using the old password for up to 30 minutes. What is the most likely cause?
⚠ Common exam trap
A common trap is assuming that password changes are instantly updated globally across all Domain Controllers. In large environments with multiple AD sites, replication latency (which defaults to 15 or 30 minutes for inter-site replication) means old credentials remain valid on non-replicated DCs for a short period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Active Directory replication delay
When a password is changed in Active Directory, the change is processed by a specific Domain Controller (DC) and urgently replicated to the PDC Emulator. However, if the RADIUS server queries a different DC (such as one in a different AD site), that DC will not know about the password change until normal replication occurs. Inter-site replication typically occurs on a schedule (often 15 to 30 minutes). During this replication window, the DC queried by the RADIUS server still holds the old password hash as valid, allowing the user to successfully authenticate with their old password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberos ticket lifetime
Why it's wrong here
Kerberos is an authentication protocol distinct from RADIUS, primarily used for authenticating users and services within a Windows Active Directory domain or similar environments. Network device authentication, especially when using a centralized system like RADIUS, does not typically rely on Kerberos tickets for the initial access control. Therefore, the lifetime of a Kerberos ticket would not impact a user's ability to authenticate to a network device with a new password via RADIUS.
- ✗
Network devices caching authentication responses
Why it's wrong here
Network devices, such as switches or wireless access points, frequently implement local caching of successful authentication responses to improve performance and reduce load on the RADIUS server. When a user successfully authenticates, the device stores this credential information or a session token for a defined period. If a user changes their password, the device might still accept the old password from its cache until that cache entry expires, leading to a temporary inconsistency.
- ✓
Active Directory replication delay
Why this is correct
Active Directory replication delay occurs when a password change made on one domain controller has not yet synchronized to all other domain controllers. If the RADIUS server queries a domain controller that has not received the updated password, authentication would fail. While replication delays can cause authentication problems, a 30-minute delay for a password change to propagate across an Active Directory forest is typically excessive for a well-configured environment, making it a less probable primary cause than device-level caching.
- ✗
RADIUS server caching credentials
Why it's wrong here
RADIUS servers generally function as authentication proxies, forwarding authentication requests from network access devices to a backend identity provider, such as Active Directory or an LDAP directory. They are not designed to cache user credentials locally for security and consistency reasons, as this would create a secondary, potentially outdated, source of truth for passwords. Instead, each authentication attempt typically triggers a real-time query to the authoritative directory service.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.