How do the three parts of AAA compare?
Authentication checks an asserted identity, authorization enforces permissions, and accounting records usage or activity. They often happen in the same session, which is why they’re easy to confuse. RFC 2903 describes a generic AAA architecture.
An audit record needs trustworthy data; hashing and encryption address different parts of protecting and checking that data.
Scroll sideways to see every column.
| Part | Question it answers | Example | Failure example |
|---|---|---|---|
| Authentication | Who are you? | Verify a sign-in credential | A stolen credential lets an attacker sign in |
| Authorization | What may you do? | Allow a support role to read a ticket | A support role can delete payroll data |
| Accounting | What happened? | Log who exported a report and when | The export leaves no useful audit record |
Is entering a username authentication?
Entering a username identifies the claimed account; proving that claim is authentication. A username tells the service which identity you’re asking to use. A password, security key or other authenticator supplies evidence for the claim.
Authentication also applies to systems. A service can authenticate another service using a certificate or other credential before accepting its request. It doesn’t have to be a person typing into a login form.
Successful authentication is evidence about identity within that method’s limits. It doesn’t prove every subsequent action is safe, or that the person still controls the session.
For certificate-based sign-in, review public and private key roles so identity verification doesn’t get confused with decrypting traffic.
A valid login may follow phishing or stolen-password reuse, so successful authentication alone doesn’t explain how the credential was obtained.
Why can I log in and still see access denied?
You can log in and still see access denied because authentication succeeded but authorization rejected the requested action. A new employee may have a valid account and still lack permission to open finance records. That is expected if their role doesn’t need those records.
Least privilege gives an identity only the access it needs for its task. Role-based access groups permissions around roles; attribute-based policies can consider factors such as department, resource sensitivity and device state.
In a question about an employee who can edit another team’s confidential records, look at permissions first. Adding another sign-in factor won’t fix an overly broad permission assignment. The permission must be corrected.
Network permission questions often involve VPN access and segmentation rules as well as the user’s application role.
Does accounting mean financial accounts?
Accounting in AAA means recording relevant activity and usage, not managing the finance department’s accounts. Useful records can include the identity, timestamp, resource, action and outcome.
An audit log could show that account analyst-17 exported a report at 14:06. That record helps an investigation, but its value depends on trustworthy timestamps, protected logs and enough detail to reconstruct the event.
Shared accounts weaken attribution because several people use the same identity. Individual accounts and protected central logging make it easier to establish who performed an action. Logs still need interpretation; an account name alone doesn’t prove which human was at the keyboard.
Logs become more useful when SIEM connects events and EDR supplies device evidence for the same session.
Some services separate identity checks and activity records onto different standard ports, such as RADIUS authentication and accounting.
Are a password and a PIN two authentication factors?
A password and a PIN are both knowledge factors, so using both doesn’t by itself create multifactor authentication. MFA uses more than one factor category, such as knowledge plus possession.
A password and a separately held security key can combine something you know with something you have. A fingerprint is a biometric characteristic, usually described as something you are. In real deployments, biometric checks often unlock an authenticator rather than being sent to a server as a standalone secret.
NIST’s authentication guidance distinguishes authenticators and their factor requirements. Count factor categories rather than the number of prompts shown to the user.
To investigate whether an account has already been misused, distinguish threat hunting from vulnerability scanning.
How do I separate AAA in an exam scenario?
Separate AAA by finding the moment when the problem occurs: proving identity, allowing an action, or recording the result. If someone signs in correctly but sees data beyond their role, the problem is authorization. If investigators lack a record of the export, it’s accounting.
Keep these steps separate even when one product provides them all. A VPN can authenticate a user, restrict their network access and record the session. That doesn’t merge the three purposes.
For a business decision about access risk, SLE and ALE calculations estimate loss rather than verify identity.
In a practical access-control task, check both the required permission and the action that must remain denied.
- 01Check identityAuthentication verifies the claimed account
- 02Check permissionAuthorization allows or denies the request
- 03Record activityAccounting records the action and outcome