Courseiva

CISSP Security and Risk Management Practice Question

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

⚠ Common exam trap

CISSP often tests the logical sequence of AAA, and candidates may confuse the order by thinking accounting comes before authorization because logs are generated during authentication, but the correct order is Authentication, Authorization, Accounting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication, Authorization, Accounting

The AAA framework defines a sequential process: Authentication verifies the identity of a subject (e.g., via password, token, or biometrics), Authorization determines what resources that authenticated subject may access, and Accounting logs the subject's activities for auditing and billing. This order is logical because you cannot authorize an unauthenticated user, and accounting requires both identity and access decisions to be meaningful. Thus, Authentication → Authorization → Accounting is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authentication, Authorization, Accounting

    Why this is correct

    This sequence correctly represents the foundational AAA framework. Authentication verifies the user's identity, establishing 'who you are.' Subsequently, Authorization determines the specific resources or actions the authenticated user is permitted to access, defining 'what you can do.' Finally, Accounting meticulously logs all user activities and resource consumption, providing a record of 'what you did' for auditing and accountability.

  • ✗

    Authorization, Authentication, Accounting

    Why it's wrong here

    This order is fundamentally flawed because authorization, which grants access permissions, cannot logically occur before authentication. An access control system must first verify the identity of a user or entity ('who you are') through authentication mechanisms. Without a confirmed identity, the system has no basis to determine what specific privileges ('what you can do') should be assigned or denied.

  • ✗

    Authentication, Accounting, Authorization

    Why it's wrong here

    Placing accounting before authorization is incorrect as it attempts to log activities before access rights are even established. The system must first authenticate the user and then authorize their specific permissions to resources. Only after authorization has determined what actions are permissible can accounting accurately record those actions in the context of granted access, ensuring proper audit trails.

  • ✗

    Accounting, Authentication, Authorization

    Why it's wrong here

    Initiating the access control process with accounting is illogical, as there are no actions to log prior to identity verification and permission assignment. Accounting's role is to record events and resource usage, which presupposes that a user has been identified and granted some level of access. Therefore, both authentication and authorization must precede any meaningful accounting activities within the system.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.