← Explorations
AAA & Security Frameworks
Authentication, Authorization, Accounting. Plus NIST, ISO, Zero Trust.

The three pillars of AAA

Every modern identity system answers these three questions in this order.

A

Authentication

"Who are you?"

Prove the identity. Password, token, fingerprint. See the Auth Factors exploration.

Means: passwords, MFA, biometrics, certificates.
A

Authorization

"What are you allowed to do?"

Decide which resources and actions the authenticated identity may use. Independent from authentication.

Means: RBAC, ABAC, ACLs, group memberships, scopes.
A

Accounting

"What did you do?"

Record the activity. Audit trails, session logs, command histories. Sometimes called "auditing" on the exam.

Means: logs, SIEM events, command logging, session recordings.
Some sources expand AAA to IAAA, adding Identification as a separate first step: typing a username CLAIMS an identity; authentication then PROVES it. CCST may use either form.
Which pillar is this?
 

AAA protocols at a glance

Which protocols support which letters, and what's special about each one.

Protocol
Authn
Authz
Acct
Notes
RADIUS
UDP 1812 (auth), UDP 1813 (acct). Combines authn+authz into one exchange. Used with 802.1X.
TACACS+
TCP 49. Cisco-favored. SEPARATES authn, authz, and acct into distinct exchanges. Encrypts the entire payload (vs RADIUS, which only encrypts the password).
Kerberos
-
-
TCP/UDP 88. Ticket-based authentication, the backbone of Active Directory. Pairs with LDAP/AD for authorization.
LDAP
-
TCP 389 (cleartext), 636 (LDAPS). Directory service. LDAP bind for authn; group membership for authz.
SAML / OIDC
-
Federation for web SSO. SAML is XML-based (enterprise); OIDC is JSON/JWT-based on top of OAuth 2.0 (modern apps).
OAuth 2.0
-
-
Authorization framework only. "Sign in with Google" actually uses OIDC on top.
802.1X
via RADIUS
via RADIUS
Port-based network access control. Wraps EAP between supplicant and authenticator; RADIUS does the actual AAA backend.

NIST Cybersecurity Framework (CSF)

The most-tested framework on the CCST. Originally five functions; CSF 2.0 (2024) added GOVERN as a sixth. Click any card for detail.

Which framework applies?
 

Core security principles

These show up in every framework and every audit question.

Zero Trust

"Never trust, always verify."

The classic model trusted everything inside the firewall: get past the perimeter, roam freely. Zero Trust assumes the network is already breached and verifies every request based on identity and context, not network location. Pairs with least privilege and microsegmentation.

Score: 0 / 0 (0%)
Streak: 0