N10-009 exam dumps

N10-009 practice question 237 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 237

Single answer3.5 Compare and contrast network access and management methods.

A network administrator needs to remotely manage branch office routers and switches across an untrusted WAN connection. Company policy requires encrypted administrative access, centralized authentication using the existing AAA server, and role-based authorization so junior technicians can view configurations but not make changes. Which management method should the administrator implement to BEST meet these requirements?

  1. A

    SSH for device access integrated with TACACS+ for centralized AAA

  2. B

    Telnet for device access integrated with RADIUS for centralized authentication

  3. C

    SNMPv2c with community strings for device management and monitoring

  4. D

    HTTP for web-based device access with local user accounts only

Show answer and explanation

Correct answer: A

Explanation

The best answer is SSH integrated with TACACS+. For Network+ objectives covering network access and management methods, candidates should distinguish between secure and insecure administrative protocols and understand how AAA technologies support centralized control. SSH is the standard replacement for Telnet because it encrypts management sessions. TACACS+ is widely used for administrative access to routers, switches, and firewalls because it separates authentication, authorization, and accounting and supports granular command authorization, which is ideal for role-based access. By contrast, RADIUS is also an AAA protocol but is more commonly used for network access scenarios such as 802.1X, VPN, and wireless authentication. SNMPv3 would be the secure version of SNMP for management traffic, but SNMPv2c specifically uses insecure community strings and is not intended to replace secure administrative logins. Best practices from network vendors and security guidance consistently recommend using SSH instead of Telnet and centralized AAA, especially TACACS+, for administrative device management.

  • A. Correct.

    Correct. SSH provides encrypted remote administrative access over untrusted networks, protecting credentials and management traffic from interception. TACACS+ is commonly used for centralized AAA in network device administration and is well suited for per-command authorization and role-based administrative control. This combination best matches the requirements for encryption, centralized authentication, and limiting junior staff to read-only or restricted privileges.

  • B. Incorrect.

    Incorrect. Telnet sends credentials and session data in cleartext, making it unsuitable for administrative access across an untrusted WAN. Although RADIUS can provide centralized authentication, it is more commonly associated with network access control and does not offer the same level of granular command authorization for device administration that TACACS+ provides. Someone might choose this because RADIUS is a valid AAA protocol, but the lack of encryption in Telnet makes this option unacceptable.

  • C. Incorrect.

    Incorrect. SNMPv2c is primarily used for monitoring and limited management, but community strings are not encrypted and function more like shared passwords than secure per-user authentication. It also does not provide the kind of interactive CLI administrative access and role-based command authorization described in the scenario. A candidate might pick this because SNMP is a management protocol, but SNMPv2c is not appropriate for secure administrative login requirements.

  • D. Incorrect.

    Incorrect. HTTP is unencrypted unless paired with TLS as HTTPS, and using local user accounts only does not satisfy the requirement for centralized authentication with the existing AAA server. While a web interface may allow administration, this option fails both the encryption and centralized AAA requirements. It is plausible because many devices do have browser-based management, but the specific controls requested are not met here.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam