Courseiva

CCNA Network Services and Security Practice Question

A network administrator is implementing 802.1X port-based authentication on a Cisco switch. The switch will act as the authenticator, and a RADIUS server will provide authentication services. Which two statements are true regarding this deployment? (Choose two.)

⚠ Common exam trap

The trap here is thinking the switch forwards EAPoL frames directly to the RADIUS server, when it actually encapsulates them into RADIUS packets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The authentication server can be a Cisco ISE appliance or any RADIUS-compliant server.

In 802.1X, the switch is the authenticator and communicates with the RADIUS server using RADIUS protocol. The supplicant communicates with the switch using EAPoL. The authentication server can be any RADIUS-compliant server, such as Cisco ISE. The switch does not forward EAPoL frames to the server; it translates them into RADIUS. The supplicant does not need the RADIUS server IP, and MAC address authentication is not the default method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The supplicant must be configured with the RADIUS server's IP address.

    Why it's wrong here

    The supplicant does not need to know the RADIUS server's IP address. The supplicant communicates only with the authenticator (switch) using EAPoL. The switch handles communication with the RADIUS server. The supplicant is typically a software client on the end device that provides credentials when prompted by the switch. Configuring the RADIUS server IP on the supplicant is unnecessary and not part of the 802.1X process.

  • ✓

    The authentication server can be a Cisco ISE appliance or any RADIUS-compliant server.

    Why this is correct

    The authentication server in 802.1X can be any RADIUS-compliant server, such as Cisco Identity Services Engine (ISE), Microsoft Network Policy Server (NPS), or FreeRADIUS. The switch acts as a RADIUS client. The server validates the supplicant's credentials and returns an accept or reject decision. Cisco ISE is a common choice in Cisco environments, but it is not the only option.

  • ✗

    The switch forwards EAPoL frames between the supplicant and the authentication server.

    Why it's wrong here

    The switch does not forward EAPoL frames directly to the RADIUS server. EAPoL is a Layer 2 protocol used between the supplicant and the authenticator. The authenticator (switch) encapsulates EAP messages into RADIUS packets and sends them to the authentication server. The RADIUS server does not understand EAPoL; it communicates via RADIUS.

  • ✗

    The switch authenticates the supplicant using its MAC address by default.

    Why it's wrong here

    By default, 802.1X uses EAP for authentication, which typically involves a username and password or a certificate, not just the MAC address. MAC authentication bypass (MAB) is an optional feature that uses the MAC address as the username and password, but it is not the default. The default behavior requires the supplicant to respond to EAPoL identity requests with credentials.

  • ✓

    The switch uses RADIUS to communicate with the authentication server.

    Why this is correct

    In 802.1X, the authenticator (switch) communicates with the authentication server using RADIUS. The switch receives EAPoL messages from the supplicant, encapsulates them into RADIUS Access-Request packets, and sends them to the RADIUS server. The server responds with Access-Challenge, Access-Accept, or Access-Reject. This is the standard communication method between the authenticator and the authentication server.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.