CCNA Network Services and Security Practice Question
A network team is deploying 802.1X on Cisco switches for wired port access control. User laptops run a supplicant that supports EAP-TLS with client certificates, and the company wants mutual authentication between the client and the authentication server. Which component in the 802.1X architecture relays EAP messages between the supplicant and the authentication server while enforcing the port state?
⚠ Common exam trap
A common mix-up: candidates confuse the authentication server's decision-making role with the authenticator's job of relaying EAP messages and controlling the port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authenticator
The 802.1X architecture defines three roles: supplicant, authenticator, and authentication server. The authenticator, which is the switch port, sits between the other two. It encapsulates EAP frames into RADIUS requests toward the server and decapsulates responses back to the supplicant, while holding the port unauthorized until the server grants access. The supplicant and server handle the endpoints of the exchange, and EAPOL is only the framing protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The supplicant
Why it's wrong here
The supplicant is the client software running on the endpoint, such as a laptop, that responds to authentication challenges. It originates EAP responses but does not relay messages to the authentication server or control the switch port state. Its role is limited to the client side of the exchange, so it cannot perform the relay function described.
- ✗
The EAP over LAN frame format
Why it's wrong here
EAPOL is the frame format used to carry EAP messages between the supplicant and the authenticator. It is a protocol encapsulation, not an architectural component. It does not make authentication decisions, relay messages to the RADIUS server, or enforce port authorization. The stem asks for the component performing relay and enforcement, which is a device role.
- ✓
The authenticator
Why this is correct
In 802.1X, the authenticator is the switch port that controls access. It relays EAP frames between the supplicant and the authentication server, encapsulating them in RADIUS when forwarding upstream. It also keeps the port in the unauthorized state until authentication succeeds, which matches the described enforcement and relay responsibilities.
- ✗
The authentication server
Why it's wrong here
The authentication server, typically RADIUS, validates credentials and returns accept or reject decisions. It does not relay messages between the supplicant and itself; the authenticator performs that relay. The server also does not directly control the physical switch port state. Its role is decision-making rather than message forwarding or port enforcement.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Troubleshoot: No IP Connectivity Between Hosts
Key term
EAP
EAP is a flexible authentication framework used in network access control, supporting multiple methods like passwords, certificates, and tokens.
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.