Which protocol allows separate authentication and authorization for wireless AP management?
Choose an answer
Tap an option to check your answer.
Correct answer: TACACS+.
Why this is the answer
TACACS+ (Terminal Access Controller Access-Control System Plus) is the correct answer because it provides separate authentication and authorization services, which is crucial for managing network devices like wireless APs. This separation allows for granular control over what an authenticated user can do. For example, an administrator can be authenticated and then authorized to perform only specific management tasks on an AP. RADIUS (Remote Authentication Dial-In User Service) combines authentication and authorization into a single process, making it less flexible for detailed access control compared to TACACS+. While RADIUS is widely used for network access authentication (e.g., Wi-Fi users), TACACS+ is preferred for device management. 802.1X is an authentication standard used for port-based network access control, often leveraging RADIUS as the backend authentication server. It's not a protocol for AP management itself. Kerberos is a network authentication protocol that grants tickets for services within a trusted domain. While it provides strong authentication, it's not typically used for the granular authorization of device management like TACACS+.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed