easyMultiple SelectObjective-mapped
SSCP Practice Question: Which TWO are components of the AAA framework?…
Which TWO are components of the AAA framework? (Choose two.)
⚠ Common exam trap
ISC2 often tests the AAA framework by including 'Auditing' as a distractor, leading candidates to confuse it with 'Accounting' because both involve logging, but Accounting is the correct term for tracking resource consumption in AAA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
Authorization (A) and Authentication (E) are two of the three core components of the AAA framework, as defined by Cisco and the IETF in RFC 2903 and RFC 2904. Authentication verifies the identity of a user or device (e.g., using RADIUS or TACACS+), while Authorization determines what resources or actions that authenticated entity is permitted to access. Together with Accounting, these three form the AAA triad used in network access control and security policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization
Why this is correct
Authorization determines access rights.
- ✗
Auditing
Why it's wrong here
Auditing is related but not a core AAA component; the term is Accounting.
- ✗
Accounting
Why it's wrong here
Accounting is part of AAA, but only two are correct; we chose Authentication and Authorization.
- ✗
Administration
Why it's wrong here
Administration is not part of AAA.
- ✓
Authentication
Why this is correct
Authentication verifies identity.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.