A+ Lesson

RADIUS, TACACS+, and Kerberos for A+

Last updated: 6/10/2026

Short answer

These items are about identity verification, not about encryption or Wi-Fi protocol labels. RADIUS is the term most likely to appear in enterprise Wi-Fi contexts where each user logs in with individual credentials. TACACS+ is often discussed around network device administration. Kerberos is tied to domain environments and ticket-based access. For A+ tasks, the technician must identify when a scenario is referring to centralized authentication rather than protocol or encryption choices.

Why it appears on the exam

- Identify RADIUS as the likely enterprise Wi-Fi authentication back end. - Distinguish authentication back ends from encryption terms and protocol names. - Recognize Kerberos as domain authentication rather than a Wi-Fi feature.

Key concepts

Concept 1

Required terms

RADIUS: Remote Authentication Dial-in User Service; a centralized authentication system commonly associated with enterprise network access, including Wi-Fi authentication scenarios. TACACS+: Terminal Access Controller Access-Control System Plus; an authentication and device-access control system primarily associated with network device administration. Kerberos: An authentication protocol commonly used in domain environments where users authenticate to access services using tickets. authentication back end: A system that verifies user identity centrally rather than relying on a single device's local password.

Example

Company wants employees to use their work accounts to join Wi-Fi rather than a shared password: answer points to RADIUS (authentication back end).

Concept 2

How RADIUS, TACACS+, and Kerberos works

These items are about identity verification, not about encryption or Wi-Fi protocol labels. RADIUS is the term most likely to appear in enterprise Wi-Fi contexts where each user logs in with individual credentials. TACACS+ is often discussed around network device administration. Kerberos is tied to domain environments and ticket-based access. For A+ tasks, the technician must identify when a scenario is referring to centralized authentication rather than protocol or encryption choices.

Example

A question asks which term is associated with domain authentication and service access: Kerberos is the category match.

Concept 3

Common confusion

Learners frequently select AES or WPA3 when the scenario is about user identity. Emphasize that authentication verifies who you are; encryption protects the data in transit; protocol labels describe the standard used for access.

Example

Company wants employees to use their work accounts to join Wi-Fi rather than a shared password: answer points to RADIUS (authentication back end).

Concept 4

Core 2 (220-1202) question cues

Identify RADIUS as the likely enterprise Wi-Fi authentication back end; Distinguish authentication back ends from encryption terms and protocol names; Recognize Kerberos as domain authentication rather than a Wi-Fi feature.

Example

A question asks which term is associated with domain authentication and service access: Kerberos is the category match.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.In an A+ question, this detail appears: Company wants employees to use their work accounts to join Wi-Fi rather than a shared password: answer points to RADIUS (authentication back end). Which option matches it?

Q2.A support ticket includes this clue: A question asks which term is associated with domain authentication and service access: Kerberos is the category match. Which concept is being tested?

Q3.An A+ support scenario describes this situation: A question asks which term is associated with domain authentication and service access: Kerberos is the category match. Which answer fits best?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8