ETExamTower
Q97Security Fundamentals

Drag and drop the statements about AAA onto the corresponding AAA services. Not all options are used. <DragDrop items={["It supports local, PPP, RADIUS, and TACACS+ options","It tracks the services that a user is using.","It records the amount of network resources consumed by the user.","It assigns per-user attributes.","It permits and denies login attempts."]} slots={[{"answer":"It tracks the services that a user is using.","id":"s1","group":"Accounting"},{"answer":"It records the amount of network resources consumed by the user.","id":"s2","group":"Accounting"},{"answer":"It supports local, PPP, RADIUS, and TACACS+ options","id":"s3","group":"Authentication"},{"answer":"It permits and denies login attempts.","id":"s4","group":"Authentication"}]} explanation={"In AAA, **Authentication** identifies the user and decides whether access is allowed, so permitting or denying login attempts belongs there. Authentication can use methods such as local databases, PPP-related authentication, RADIUS, and TACACS+. **Accounting** logs what the user did after access is granted, including which services were used and how much network resource consumption occurred. **Authorization** is the AAA function that assigns permissions or per-user attributes, so that statement is the distractor.\n\n**Learn more:** [Authentication, Authorization, and Accounting Configuration Guide](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-mt/sec-usr-aaa-15-mt-book.html)"} reuse={false} />

← → navigate · a answer
Discussion · 4
9
Per user attributes sounds like authorization. Since each user could be set up to have different authorizations for different software and applications.
3
The given answer seems correct. Per user attributes would be referred to as CoA (Change of Authorization).
2
In the AAA environment I run, there are attributes returned in the authorization profile. These are called Cisco AV pairs, which stands for "attribute values" https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215525-use-radius-for-device-administration-wit.html
1
Authorization: It supports local, PPP, RADIUS, and TACACS+ options. It assigns per-user attributes. Accounting: It tracks the services that a user is using. It records the amount of network resources used by the user.