Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Distinguish authentication from authorization and explain why the order matters
- Explain MFA and SSO and how each affects identity verification and risk
- Compare RADIUS, TACACS+, LDAP, and SAML as authentication and directory protocols
- Explain least privilege and role-based access control (RBAC)
- Describe time-based authentication and geofencing as contextual access controls
Key Terms
| Term | Definition |
|---|---|
| Authentication | The process of verifying that a user or device is who it claims to be |
| Authorization | The process of determining what an authenticated user or device is permitted to do |
| MFA (Multifactor Authentication) | Requiring two or more distinct factors — something you know, have, or are — to verify identity |
| RADIUS | An AAA protocol commonly used for network device, VPN, and wireless authentication |
| RBAC (Role-Based Access Control) | An access control model that assigns permissions based on a user’s role rather than individually |
Explanation
From Certificates to Identity
The previous lesson covered certificates as one way of proving identity — a device or server presenting a certificate is, in effect, authenticating itself. This lesson broadens that idea to the full range of ways people and systems verify who they are and control what they’re allowed to do once that identity is established.Authentication vs. Authorization: Two Different Questions
These two terms get used almost interchangeably in casual conversation, but they answer genuinely different questions, and they happen in a specific order:
- Authentication answers “who are you?” — verifying identity through a password, a certificate, a biometric scan, or some combination of factors.
- Authorization answers “what are you allowed to do?” — determining, only after identity has been confirmed, what resources and actions that verified identity has permission to access.

Authentication always has to happen first; authorization decisions are meaningless without a confirmed identity to apply them to. A system can authenticate someone successfully and still deny them access to a specific resource — that denial is an authorization decision, not an authentication failure.
Strengthening Authentication: MFA and SSO
MFA (Multifactor Authentication) requires two or more distinct factors drawn from different categories — something you know (a password), something you have (a hardware token or a phone receiving a code), and something you are (a fingerprint or other biometric). Requiring multiple factors from different categories means a single compromised factor, like a stolen password alone, isn’t enough to succeed.
SSO (Single Sign-On) lets a user authenticate once and gain access to multiple separate systems without logging in again for each one. This is a genuine convenience and reduces password fatigue, but it also concentrates risk: if the SSO credential itself is compromised, an attacker potentially gains access to every system that credential unlocks, rather than just one. This is exactly why pairing SSO with MFA is such a common combination — SSO’s convenience without MFA’s added verification would concentrate risk without adequately protecting against it.
Centralized Authentication Protocols: RADIUS, TACACS+, LDAP, and SAML
Several protocols exist specifically to centralize authentication rather than managing credentials separately on every device:
RADIUS is an AAA (Authentication, Authorization, Accounting) protocol commonly used to authenticate users connecting through network devices — VPN connections, wireless network logins, and switch port authentication all commonly rely on RADIUS. RADIUS combines authentication, authorization, and accounting into a single exchange.TACACS+ serves a similar overall purpose but separates authentication, authorization, and accounting into distinct, independently controllable processes. It’s commonly used specifically for administrative access to network devices — controlling and logging exactly which commands an administrator is permitted to run, not just whether they can log in at all.
LDAP (Lightweight Directory Access Protocol) is a protocol for querying and maintaining directory information — user accounts, group memberships, organizational structure — typically over port 389, or port 636 for LDAPS, its encrypted variant. LDAP itself doesn’t perform authentication so much as store and provide the directory information other systems authenticate against.SAML (Security Assertion Markup Language) is an XML-based standard that enables SSO across different organizations or domains — allowing a user authenticated by one organization’s identity provider to access a service hosted by a completely separate organization, without that second organization needing its own separate credential for that user.

A useful distinction to hold onto: RADIUS and TACACS+ are both AAA protocols focused on network access and device administration; LDAP is a directory protocol supplying identity information; SAML is a federation standard enabling cross-organization SSO specifically for web-based services.
Least Privilege and Role-Based Access Control
Least privilege is a foundational access control principle: grant users only the minimum access actually necessary to perform their job, nothing more. This limits the damage a compromised account can do, since even a successfully authenticated, malicious session is still constrained by whatever authorization limits were already in place.
RBAC (Role-Based Access Control) implements least privilege at scale by assigning permissions to defined roles rather than to individuals directly. A new employee is assigned to the appropriate role and immediately inherits exactly the access that role is defined to have — and when someone changes roles or leaves, adjusting or removing that one role assignment updates their access accordingly, without needing to manually track down and revoke a long list of individually granted permissions.
Time-Based Authentication and Geofencing
Two additional controls add context-aware conditions on top of standard authentication:
- Time-based authentication includes both time-limited one-time codes (like a TOTP code that expires after 30 seconds, making a captured code quickly useless to an attacker) and access restrictions tied to specific hours (only allowing certain logins during business hours, for instance).
- Geofencing restricts access based on physical or geographic location, flagging or blocking a login attempt that originates from an unexpected or disallowed region entirely.

Both controls work by adding a contextual condition beyond simply “was the right credential presented” — even a technically correct credential can be treated as suspicious or denied outright if it arrives at the wrong time or from the wrong place.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- A login prompt asking for identity verification is authentication; a subsequent “access denied” for a specific resource, after successful login, is an authorization decision.
- A login requiring both a password and a code sent to a phone is MFA, spanning something-you-know and something-you-have.
- Network device administrators logging in with command-level access logging point to TACACS+; VPN or wireless users authenticating through a central server point to RADIUS.
- A user’s access changing automatically because their assigned role changed, without any individual permission being manually adjusted, describes RBAC in action.
Common Exam Traps
- Authentication and authorization are sequential and distinct — never assume one implies the other. Successful login (authentication) doesn’t guarantee access to every resource (authorization is a separate check).
- RADIUS and TACACS+ are not interchangeable, despite serving a similar overall AAA purpose. RADIUS combines AAA into one exchange; TACACS+ separates the three functions, and is the more common choice specifically for granular device administration control.
- LDAP is a directory protocol, not itself a full authentication mechanism. Other systems query LDAP for identity information as part of their own authentication process.
- SSO’s convenience comes with a real security tradeoff — concentrated risk — which is exactly why it’s so often paired with MFA, not treated as a security measure entirely on its own.
- Least privilege and RBAC are related but distinct concepts. Least privilege is the underlying principle; RBAC is one common method of actually implementing that principle at scale through defined roles.
Lesson 4.1.3 Practice Quiz — Authentication, Authorization & Identity Management
17 questions covering authentication vs. authorization, MFA, SSO, RADIUS, TACACS+, LDAP, SAML, RBAC, and contextual access controls.
N10-009 · Domain 4.1Summary
Authentication verifies identity ("who are you"); authorization determines permitted actions ("what can you do") — authentication always happens first, and the two are never interchangeable.
MFA requires multiple distinct factor categories to strengthen identity verification; SSO trades convenience for concentrated risk, which is why it's commonly paired with MFA.
RADIUS and TACACS+ are AAA protocols for network access and device administration (RADIUS combining AAA into one exchange, TACACS+ separating them); LDAP stores directory information other systems authenticate against; SAML enables cross-organization web SSO.
Least privilege grants only the minimum access necessary, and RBAC implements that principle at scale by assigning permissions to roles rather than individuals.
Time-based authentication and geofencing add contextual conditions — timing and location — on top of standard credential verification.



