Courseiva
Infrastructure →easyMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is configuring a switch to support 802.1X authentication for wired clients. The requirement is to authenticate users against a centralized RADIUS server and assign dynamic VLANs based on the user's role. Which command must be configured on the switch to enable 802.1X authentication globally?

⚠ Common exam trap

Watch out — candidates often confuse the global enablement command with interface-level or AAA commands that are also part of 802.1X configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dot1x system-auth-control

To enable 802.1X authentication globally on a Cisco switch, the 'dot1x system-auth-control' command must be configured. This command activates the 802.1X process and allows the switch to act as an authenticator. Other commands, such as those for RADIUS or interface-level settings, are necessary but do not globally enable 802.1X.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aaa authentication dot1x default group radius

    Why it's wrong here

    The command 'aaa authentication dot1x default group radius' specifies the authentication method list for 802.1X, directing authentication requests to a RADIUS server group. While this command is necessary for 802.1X to work with RADIUS, it does not globally enable 802.1X on the switch. It must be used in conjunction with 'dot1x system-auth-control'. Alone, it does not activate 802.1X authentication.

  • ✓

    dot1x system-auth-control

    Why this is correct

    The command 'dot1x system-auth-control' enables 802.1X authentication globally on a Cisco switch. It is a prerequisite for configuring 802.1X on individual interfaces. Without this command, 802.1X authentication will not function, even if interface-level commands are configured. This command allows the switch to act as an authenticator and communicate with the RADIUS server to authenticate supplicants.

  • ✗

    authentication port-control auto

    Why it's wrong here

    The command 'authentication port-control auto' is an interface-level command that enables 802.1X authentication on a specific port. It does not enable 802.1X globally. It is used after global configuration and specifies that the port will use 802.1X authentication. Without the global command, this interface command alone will not enable 802.1X. Thus, it is not the correct answer for global enablement.

  • ✗

    dot1x pae authenticator

    Why it's wrong here

    The command 'dot1x pae authenticator' is configured on an interface to set the Port Access Entity (PAE) role as the authenticator. It is an interface-level command, not a global command. While it is part of 802.1X configuration, it does not enable 802.1X globally. The global command 'dot1x system-auth-control' is required first. Therefore, this option is not correct for enabling 802.1X globally.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.