Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

A financial institution uses a RADIUS server for centralized authentication of its VPN users. A security administrator notices that authentication requests from a new VPN concentrator are being rejected, while requests from other devices work fine. The RADIUS server logs show that the shared secret does not match. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that any authentication failure is due to user credentials or certificates, when the specific log message points to a device-level shared secret mismatch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VPN concentrator is configured with the wrong shared secret.

RADIUS uses a shared secret between the client (VPN concentrator) and the server to authenticate and encrypt certain attributes. When the shared secret does not match, the server rejects requests from that client. The logs explicitly indicate a shared secret mismatch, so the most likely cause is that the new VPN concentrator has been configured with an incorrect shared secret. Other options would produce different symptoms or logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The RADIUS server's certificate has expired.

    Why it's wrong here

    RADIUS typically uses a shared secret rather than certificates for client authentication, though certificates can be used in some implementations. An expired certificate would cause TLS errors, not a shared secret mismatch. The specific log message about shared secret mismatch rules out certificate issues.

  • ✗

    The user accounts are not configured with the correct password policy.

    Why it's wrong here

    Password policy issues would affect all users or specific users, but the problem is isolated to one VPN concentrator. The shared secret mismatch is a device-level configuration issue, not a user password policy problem. Therefore, this option does not explain the observed behavior.

  • ✗

    The VPN concentrator is not included in the RADIUS server's list of authorized clients.

    Why it's wrong here

    If the VPN concentrator were not an authorized client, the RADIUS server would typically drop the request without processing it, often logging an 'unknown client' error. A shared secret mismatch indicates the client is recognized but the secret is incorrect. Thus, this is not the most likely cause.

  • ✓

    The VPN concentrator is configured with the wrong shared secret.

    Why this is correct

    RADIUS clients and servers authenticate each other using a shared secret. If the shared secret on the VPN concentrator does not match the one configured on the RADIUS server, authentication requests will be rejected. The logs indicating a shared secret mismatch point directly to this configuration error on the new device.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.