CCNP Architecture Practice Question
A network engineer is configuring a Cisco Catalyst 9000 switch for a new access layer. The engineer needs to enable a feature that allows the switch to authenticate endpoints using 802.1X and then assign them to a specific VLAN based on the result. Which Cisco feature should be configured to dynamically assign VLANs?
⚠ Common exam trap
The trap here is selecting VMPS, which is an older dynamic VLAN assignment method based on MAC addresses, not 802.1X authentication, and is not supported on modern Catalyst switches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X with VLAN assignment via RADIUS
The correct feature is 802.1X with VLAN assignment via RADIUS. When an endpoint authenticates via 802.1X, the switch acts as an authenticator and relays credentials to a RADIUS server like Cisco ISE. Upon successful authentication, the RADIUS server can return tunnel attributes that specify the VLAN. The switch then dynamically assigns the port to that VLAN, allowing for role-based access control and simplified VLAN management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Private VLAN (PVLAN) edge
Why it's wrong here
PVLANs are used to isolate ports within a VLAN, providing Layer 2 separation. They do not dynamically assign VLANs based on authentication. PVLAN edge, also known as protected port, prevents communication between ports on the same switch. It is a security feature but does not integrate with 802.1X for VLAN assignment. Configuring PVLAN would not achieve the desired dynamic VLAN assignment.
- ✗
Dynamic ARP Inspection (DAI)
Why it's wrong here
DAI is a security feature that validates ARP packets to prevent ARP spoofing. It does not assign VLANs based on authentication. DAI works by intercepting ARP packets and comparing them against a DHCP snooping database. While it enhances security, it is unrelated to dynamic VLAN assignment. Configuring DAI would not fulfill the requirement for 802.1X-based VLAN assignment.
- ✓
802.1X with VLAN assignment via RADIUS
Why this is correct
When 802.1X is configured with a RADIUS server, such as Cisco ISE, the server can return attributes that instruct the switch to place the authenticated endpoint into a specific VLAN. This is done using the IETF RADIUS attribute Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID. The switch then dynamically assigns the port to that VLAN. This feature is supported on Catalyst 9000 switches and is the standard method for dynamic VLAN assignment.
- ✗
VLAN Membership Policy Server (VMPS)
Why it's wrong here
VMPS is a legacy Cisco feature that dynamically assigns VLANs based on the source MAC address of a device. It is not based on 802.1X authentication and is largely deprecated in modern networks. VMPS requires a separate VMPS server and does not integrate with 802.1X. It would not meet the requirement for authentication-based VLAN assignment on a Catalyst 9000 switch.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.