Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is deploying a new branch office with a single Cisco Catalyst switch. The branch requires that all access ports automatically authenticate devices using 802.1X with RADIUS, but also allow unauthenticated devices to be placed into a guest VLAN. Which feature must be configured on the switch to meet this requirement?

⚠ Common exam trap

It's easy for candidates to confuse 802.1X with MAC authentication bypass or web authentication, which serve different purposes and do not provide the exact combination of 802.1X and guest VLAN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 802.1X authentication with a guest VLAN on the access ports.

The requirement is to authenticate devices using 802.1X with RADIUS and also provide a guest VLAN for unauthenticated devices. The 802.1X with guest VLAN feature on Cisco switches accomplishes this by assigning authenticated users to a VLAN and unauthenticated users to a guest VLAN. This is a standard implementation for branch offices needing both secure and guest access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure 802.1X authentication with a guest VLAN on the access ports.

    Why this is correct

    Configuring 802.1X with a guest VLAN allows authenticated devices to be placed into a VLAN after successful RADIUS authentication, while unauthenticated devices are assigned to a separate guest VLAN. This meets the branch requirement exactly. The guest VLAN feature is specifically designed for this scenario and is supported on Cisco Catalyst switches.

  • ✗

    Configure Web Authentication (WebAuth) with a guest VLAN on the access ports.

    Why it's wrong here

    WebAuth redirects users to a web portal for authentication, which is useful for guest access but does not automatically authenticate devices via 802.1X with RADIUS. The scenario explicitly requires 802.1X authentication, so WebAuth alone is not the correct solution, although it could be used in conjunction with 802.1X in some designs.

  • ✗

    Configure MAC authentication bypass (MAB) with a guest VLAN on the access ports.

    Why it's wrong here

    MAB is used for devices that do not support 802.1X, such as printers or legacy devices. It authenticates based on MAC address, but it does not automatically provide a guest VLAN for unauthenticated devices unless combined with other features. The scenario requires 802.1X authentication, so MAB alone is insufficient.

  • ✗

    Configure port security with a guest VLAN on the access ports.

    Why it's wrong here

    Port security restricts the number of MAC addresses allowed on a port and can take actions like shutdown or restrict, but it does not provide 802.1X authentication or a guest VLAN for unauthenticated devices. It is a layer 2 security feature, not an authentication mechanism, and does not meet the requirement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.