220-1101 exam dumps

220-1101 practice question 96 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 96

Single answerAuthentication, Authorization, and Accounting (AAA)

A company uses a VPN appliance integrated with a central AAA server for remote access. A sales employee reports that they can log in to the VPN successfully with their username and password, but they receive a message that they are not permitted to access the internal CRM application. The security administrator wants to determine which part of AAA is working and which part is failing in this situation. Which option BEST describes the issue?

  1. A

    Authentication is failing because the user cannot access the CRM application after signing in.

  2. B

    Authorization is failing because the user is successfully verified but does not have permission to access the CRM application.

  3. C

    Accounting is failing because the VPN appliance is not tracking the user's session correctly.

  4. D

    Encryption is failing because the CRM application is not available after the VPN connection is established.

Show answer and explanation

Correct answer: B

Explanation

The key to this question is separating the three AAA functions. Authentication answers, "Who are you?" Authorization answers, "What are you allowed to access?" Accounting answers, "What did you do, and when?" In the scenario, the employee successfully signs in to the VPN, so authentication is functioning. The failure occurs when trying to access a specific internal resource, which points to authorization, typically implemented through access control lists, role-based access control, security groups, or application permissions. Accounting would be relevant if the administrator needed to review logs showing the login attempt, access denial, or session details, but it is not the cause of the denied CRM access itself. This aligns with standard AAA concepts commonly documented in vendor and security guidance, including NIST access control principles and enterprise identity management best practices.

  • A. Incorrect.

    This is incorrect. Authentication is the process of verifying identity, such as validating a username, password, smart card, or biometric factor. In this scenario, the employee is able to log in to the VPN successfully, which indicates authentication has already succeeded. A common misconception is to assume that any access problem after login is an authentication issue, but successful sign-in means identity verification worked.

  • B. Correct.

    This is correct. Authorization determines what an authenticated user is allowed to access, such as specific applications, folders, network segments, or services. Because the user can authenticate to the VPN but cannot access the internal CRM application, the likely problem is that their permissions, group membership, access control policy, or role assignment does not allow CRM access. This is the best match for the scenario.

  • C. Incorrect.

    This is incorrect. Accounting refers to logging, tracking, and auditing user activity, such as connection times, session duration, resource usage, and access attempts. Even if accounting were misconfigured, that would not typically prevent a properly authenticated user from accessing a specific application. Someone might choose this option because AAA includes accounting, but the symptom described is about access permission, not session logging.

  • D. Incorrect.

    This is incorrect. Encryption protects data confidentiality in transit, such as when VPN tunnels use secure protocols to protect traffic. If encryption were failing, the user would more likely experience connection failures, tunnel negotiation issues, certificate warnings, or unreadable traffic, not a specific denial of access to one internal application after successful VPN login. This distractor targets the misconception that all secure remote-access problems are encryption problems.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam