Courseiva
Security →easyMultiple Choice

CCNP Security Practice Question

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?

⚠ Common exam trap

It's easy for candidates to confuse authentication protocols like EAP-TLS or MS-CHAPv2 with transport encryption mechanisms, leading to the selection of an option that secures client authentication but not the RADIUS transport.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RADIUS over TLS (RadSec)

RadSec (RADIUS over TLS) is the correct protocol to encrypt RADIUS communication between a WLC and a RADIUS server. It uses TLS to secure the entire RADIUS packet, ensuring confidentiality and integrity. Other options either refer to authentication methods or do not provide native encryption for RADIUS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RADIUS with IPsec

    Why it's wrong here

    While IPsec can be used to secure RADIUS traffic, it is not a native RADIUS security mechanism and is typically used for site-to-site VPNs. RadSec is the standard for encrypting RADIUS. This option is incorrect because it is not the typical or recommended approach for WLC-to-RADIUS communication.

  • ✓

    RADIUS over TLS (RadSec)

    Why this is correct

    RadSec (RADIUS over TLS) encrypts RADIUS packets using TLS, providing secure communication between the WLC and the RADIUS server. This protects credentials and attributes from eavesdropping. It is the recommended method for securing RADIUS traffic in modern deployments.

  • ✗

    RADIUS with MS-CHAPv2

    Why it's wrong here

    MS-CHAPv2 is an authentication protocol used within RADIUS, not a transport encryption method. It does not encrypt the RADIUS communication itself. This option is incorrect because it does not provide encryption for the RADIUS packets between the WLC and the server.

  • ✗

    RADIUS with EAP-TLS

    Why it's wrong here

    EAP-TLS is an authentication method used between the supplicant and the authentication server, not between the WLC and the RADIUS server. It secures the client authentication but does not encrypt the RADIUS protocol itself. This option is incorrect because it confuses the authentication method with the transport security.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.