Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is deploying a new branch office with a Cisco Catalyst 9200 switch. The security policy requires that any endpoint connecting to access ports must be authenticated before being granted network access, and unauthenticated devices must be placed into a restricted VLAN. The administrator wants to minimize configuration on the switch and rely on the authentication server to assign the VLAN dynamically. Which 802.1X feature should be configured on the switch to meet these requirements?

⚠ Common exam trap

Many candidates confuse port security or MAB with 802.1X, which actually provides authentication and dynamic VLAN assignment through RADIUS attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 802.1X with VLAN assignment via RADIUS attributes.

The requirement is to authenticate endpoints and dynamically assign VLANs based on authentication server response. 802.1X with RADIUS attributes allows the switch to act as an authenticator, passing credentials to a RADIUS server, which can then return VLAN assignment attributes. This ensures only authenticated devices gain access, and unauthenticated devices can be placed in a restricted VLAN. Other options either do not authenticate or do not provide dynamic VLAN assignment based on user identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure 802.1X with VLAN assignment via RADIUS attributes.

    Why this is correct

    This is the correct approach. 802.1X authentication allows the switch to authenticate endpoints using credentials (e.g., username/password or certificate) against a RADIUS server like Cisco ISE. The server can return attributes such as Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID to dynamically assign the endpoint to a specific VLAN. This meets the requirement of authenticating endpoints and placing unauthenticated devices into a restricted VLAN (e.g., a guest VLAN) if configured.

  • ✗

    Configure port security with sticky MAC addresses and a violation action of restrict.

    Why it's wrong here

    Port security limits the number of MAC addresses on a port and can take action on violation, but it does not authenticate endpoints. It is a Layer 2 security feature that can restrict access based on MAC addresses, but it does not interact with an authentication server to dynamically assign VLANs. The requirement for authentication and dynamic VLAN assignment is not met by port security alone.

  • ✗

    Configure Web Authentication (WebAuth) with a guest VLAN.

    Why it's wrong here

    WebAuth is used for guest access where users authenticate via a web portal. It does not provide the same level of security as 802.1X and is typically used for guest or BYOD scenarios. While it can assign a VLAN, it does not authenticate endpoints before granting access in the same way 802.1X does. The requirement for endpoints to be authenticated before access suggests 802.1X is more appropriate.

  • ✗

    Configure MAC Authentication Bypass (MAB) with a fallback VLAN.

    Why it's wrong here

    MAB is used for devices that do not support 802.1X supplicant software, such as printers or cameras. It uses the device's MAC address as the credential. While it can assign a VLAN, it does not authenticate the user or device via 802.1X credentials. The requirement specifies endpoints must be authenticated, implying 802.1X, and MAB alone does not provide the dynamic VLAN assignment based on user identity that the authentication server can provide.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.