About this interactive
AAA stands for authentication, authorization, and accounting, and a real AAA server writes all three into the same log. This activity hands you lines from that log and asks one question of each: what was the system doing when it wrote this line?
Authentication is proving who you are. A password being checked, a one-time code being requested, a device certificate being verified, a second factor being approved or timing out: each of these is the system deciding whether you really are the person or device you claim to be. A rejected password is an authentication failure, because the question that failed was about identity.
Authorization is what you are allowed to do once your identity is settled. A switch permitting or denying a command, a user being placed on a particular VLAN, a VPN limiting a contractor to one network, a file share refusing a write because the account is read-only: each of these is a decision about permission, not about identity. The tricky lines are the ones that say no. "Command reload denied" sounds like a failed login, but the user was already logged in; the system knew exactly who they were and decided they could not do that. Likewise, a RADIUS Access-Accept that hands back a VLAN number looks like a login success, but the part the line is recording is where that user is allowed to go.
Accounting is recording what happened. Session start and stop records, running totals of time and data, a log of the commands someone actually ran, a change log, a record of who opened a file, and saved document versions are all the accounting function: tracking what is happening and what is changing on the network. Because every line in this activity is a log entry, being logged is not the clue. Ask what the entry is about. A permit decision for a command is authorization; a record that the same command was run is accounting.
The protocols carry all three. RADIUS uses Access-Request, Access-Challenge, Access-Accept and Access-Reject for its login exchange and separate Accounting-Request messages to record sessions. TACACS+, used for administrator access to network devices, labels its messages authen, author and acct. Diameter, the successor to RADIUS, has its own authentication answers and accounting requests. The protocol name alone never tells you the bin; the event does.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →