Courseiva
Infrastructure →easyMultiple Choice

CCNP Infrastructure Practice Question

A network administrator is configuring a Cisco IOS switch to authenticate users via 802.1X. The administrator wants to ensure that if the RADIUS server is unreachable, users are placed into a guest VLAN with limited access. Which feature should be configured to achieve this?

⚠ Common exam trap

Many exam-takers confuse authentication failure (wrong credentials) with server unreachability; the commands for each are different, and only the server dead action provides the guest VLAN when the RADIUS server is down.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure authentication event server dead action authorize vlan 100 under the interface.

To place users into a guest VLAN when the RADIUS server is unreachable, the authentication event server dead action authorize vlan command must be configured on the interface. This command triggers the fallback VLAN when the server is marked dead. The other options address different authentication events or host modes and do not provide the required server-dead fallback.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure authentication host-mode multi-auth under the interface.

    Why it's wrong here

    The authentication host-mode multi-auth command allows multiple devices to authenticate independently on a single port. It does not provide any fallback VLAN for server unreachability. This option is unrelated to the requirement of placing users into a guest VLAN when the RADIUS server is down.

  • ✗

    Configure authentication open under the interface.

    Why it's wrong here

    The authentication open command allows traffic to flow before authentication, but it does not assign a guest VLAN when the RADIUS server is unreachable. It is used to provide limited access for devices that do not support 802.1X, but it does not specifically handle server dead scenarios. This option does not meet the requirement.

  • ✓

    Configure authentication event server dead action authorize vlan 100 under the interface.

    Why this is correct

    The authentication event server dead action authorize vlan 100 command instructs the switch to place the port into VLAN 100 if the RADIUS server is considered dead (unreachable). This provides a fallback for users when the authentication server cannot be contacted, allowing limited access as defined by the guest VLAN. This is the correct feature for the scenario.

  • ✗

    Configure authentication event fail action authorize vlan 100 under the interface.

    Why it's wrong here

    The command authentication event fail action authorize vlan 100 is used to assign a VLAN when authentication fails (e.g., wrong credentials), not when the RADIUS server is unreachable. For server unreachability, the correct command is authentication event server dead action authorize vlan. This option addresses a different failure scenario.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.