CCNP Infrastructure Practice Question
A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will use 802.1X authentication with EAP-TLS. The switch port must be configured to allow multiple hosts, but only one host should be authenticated. Which command should be used to enable this behavior?
⚠ Common exam trap
The trap here is assuming that allowing multiple hosts always requires multi-auth mode, when multi-host mode is specifically designed for a single authentication for multiple devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication host-mode multi-host
The requirement is to allow multiple hosts on a switch port while authenticating only one host. This is exactly the behavior of multi-host mode, where the first host authenticates and subsequent hosts are allowed without authentication. Multi-auth would authenticate each host individually, multi-domain is for voice and data domains, and single-host denies additional hosts. Thus, multi-host mode is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
authentication host-mode multi-host
Why this is correct
Multi-host mode allows multiple hosts to connect to a single port, but only the first host is authenticated. Once that host is authenticated, all other hosts are granted access without individual authentication. This matches the scenario where multiple hosts are allowed but only one host should be authenticated, making it the correct command.
- ✗
authentication host-mode multi-auth
Why it's wrong here
Multi-auth mode allows multiple hosts to be authenticated independently on the same port. However, the scenario requires that only one host be authenticated, while multiple hosts are allowed. Multi-auth would authenticate each host separately, which does not meet the requirement of a single authentication for multiple devices. Therefore it is not the correct choice.
- ✗
authentication host-mode single-host
Why it's wrong here
Single-host mode allows only one host to be authenticated and any additional hosts are denied access. This contradicts the requirement to allow multiple hosts on the port. Therefore it is not the correct configuration for this scenario.
- ✗
authentication host-mode multi-domain
Why it's wrong here
Multi-domain mode is used to authenticate one device in the data domain and one in the voice domain, typically for an IP phone and a PC. It does not allow multiple hosts in the same domain. Since the requirement is to allow multiple hosts but authenticate only one, multi-domain is not suitable because it limits the number of devices per domain.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.