100-160 exam dumps

100-160 practice question 32 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 32

Select 3

A company is implementing a new remote access solution that requires strict user authentication and secure access to its internal resources. The IT team has decided to use a RADIUS server for authentication and enforce multifactor authentication (MFA). Which of the following steps are necessary to implement this solution successfully?

  1. A

    Configure the RADIUS server to communicate with a directory service like Active Directory for user authentication.

  2. B

    Require users to set up MFA using a combination of something they know (like a password) and something they have (like a mobile authenticator app).

  3. C

    Disable accounting on the RADIUS server to reduce logging overhead and improve performance.

  4. D

    Implement a strong password policy that enforces complexity, expiration, and reuse restrictions.

  5. E

    Allow users to bypass the RADIUS server during peak hours to avoid authentication delays.

Show answer and explanation

Correct answers: A, B, D

Explanation

To securely implement a remote access solution with RADIUS and MFA, it is crucial to integrate the RADIUS server with a directory service to authenticate user credentials, enforce multifactor authentication for added security, and establish a strong password policy to reduce the risk of compromised passwords. Disabling accounting or bypassing authentication mechanisms compromises security and should be avoided as these actions weaken the AAA framework.

  • A. Correct.

    Configuring the RADIUS server to communicate with a directory service like Active Directory ensures that user credentials are validated against an existing database and integrates with the organization's identity management system.

  • B. Correct.

    Multifactor authentication (MFA) enhances security by requiring two or more factors of authentication, such as a password and a mobile authenticator app, reducing the risk of unauthorized access.

  • C. Incorrect.

    Disabling accounting on the RADIUS server is not recommended. Accounting is a key feature of AAA (Authentication, Authorization, and Accounting) and is necessary for tracking access and usage for auditing and compliance.

  • D. Correct.

    Implementing a strong password policy strengthens the overall security posture, ensuring passwords are difficult to guess and are periodically changed to mitigate risks from compromised credentials.

  • E. Incorrect.

    Allowing users to bypass the RADIUS server undermines the security framework and creates vulnerabilities that can be exploited by attackers.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam