CCNP Security Practice Question
A network administrator is deploying Cisco Identity Services Engine (ISE) for wired 802.1X authentication on a Cisco Catalyst 9200 switch. The RADIUS server is reachable at 10.10.10.50 with shared secret 'C1sco123'. The administrator wants the switch to authenticate users before granting access to the data VLAN, and to place unauthenticated devices into a restricted VLAN. Which command sequence correctly enables 802.1X on a switch port?
⚠ Common exam trap
It's easy for candidates to confuse the authenticator role with the supplicant role, or selecting force-authorized instead of auto, which would bypass authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
802.1X on a Cisco switch requires enabling AAA, defining the RADIUS server with the correct ports and key, and configuring the interface as an authenticator with 'authentication port-control auto'. The switch acts as the authenticator, ISE as the authentication server, and the endpoint as the supplicant. Using 'force-authorized' bypasses authentication, TACACS+ is not used for 802.1X, and legacy ports 1645/1646 are incorrect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control force-authorized; dot1x pae authenticator
Why it's wrong here
'authentication port-control force-authorized' places the port permanently in the authorized state, bypassing 802.1X authentication entirely. The scenario requires authentication before granting access, and force-authorized would allow all traffic without any RADIUS exchange. This command is used for testing or for ports that must remain open, not for enforcing 802.1X.
- ✗
aaa new-model; tacacs server ISE; address ipv4 10.10.10.50; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae supplicant
Why it's wrong here
TACACS+ is an authorization/accounting protocol, not used for 802.1X authentication; ISE acts as a RADIUS server for 802.1X. Additionally, 'dot1x pae supplicant' configures the port as a supplicant (client), not as an authenticator. The switch must be the authenticator, so this combination is incorrect for the scenario.
- ✗
aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1645 acct-port 1646; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
Why it's wrong here
The RADIUS ports 1645 and 1646 are legacy ports; modern RADIUS uses 1812 for authentication and 1813 for accounting. Configuring the legacy ports may cause the switch to fail to communicate with ISE, resulting in authentication failures. The correct ports are 1812 and 1813, making this option incorrect.
- ✓
aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
Why this is correct
This sequence enables AAA with 'aaa new-model', configures the ISE RADIUS server with the correct ports and key, then on the interface enables 802.1X port-based authentication with 'authentication port-control auto' and designates the switch port as an authenticator with 'dot1x pae authenticator'. This is the correct method to authenticate before granting access and to use an auth-fail VLAN if configured.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.