Courseiva
Security →mediumMultiple Select

CCNP Security Practice Question

A network engineer is implementing 802.1X authentication on a Cisco switch. The engineer wants to ensure that the switch dynamically assigns a VLAN to the port based on the user's identity, and that the VLAN assignment is enforced by the authentication server. Which two components are required to achieve this? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any security feature like MACsec or DHCP snooping contributes to dynamic VLAN assignment, when only RADIUS and its attributes are relevant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the authentication server to return the appropriate RADIUS attributes, such as Tunnel-Type and Tunnel-Private-Group-ID.

Dynamic VLAN assignment requires the switch to authenticate users via RADIUS and receive VLAN information from the RADIUS server. The server must return the appropriate tunnel attributes (Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-ID) in the Access-Accept message. These two components together allow the switch to place the user into the correct VLAN automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MACsec on the switch port to encrypt the authentication exchange.

    Why it's wrong here

    MACsec encrypts traffic at Layer 2 but is not required for 802.1X authentication or dynamic VLAN assignment. While it can secure the link, it does not play a role in receiving or enforcing VLAN assignments from the authentication server. Enabling MACsec would not contribute to the dynamic VLAN feature and is not a required component.

  • ✗

    Enable DHCP snooping on the switch to validate the user's IP address.

    Why it's wrong here

    DHCP snooping is a security feature that filters DHCP messages but is not involved in 802.1X authentication or dynamic VLAN assignment. While it can be part of a broader security posture, it does not provide the RADIUS attributes needed for VLAN assignment. Enabling DHCP snooping would not achieve the goal of dynamic VLAN assignment based on user identity.

  • ✓

    Configure the authentication server to return the appropriate RADIUS attributes, such as Tunnel-Type and Tunnel-Private-Group-ID.

    Why this is correct

    For dynamic VLAN assignment, the RADIUS server must send specific attributes in the Access-Accept message: Tunnel-Type (VLAN), Tunnel-Medium-Type (802), and Tunnel-Private-Group-ID (the VLAN ID). These attributes tell the switch which VLAN to assign to the port. Without these attributes, the switch cannot dynamically place the user into the correct VLAN.

  • ✓

    Configure the switch to use RADIUS for authentication and authorization.

    Why this is correct

    RADIUS is the protocol used to communicate with the authentication server (such as Cisco ISE) to authenticate users and receive authorization attributes like VLAN assignment. Without RADIUS, the switch cannot receive dynamic VLAN information from the server. Therefore, configuring RADIUS is essential for dynamic VLAN assignment based on user identity.

  • ✗

    Configure the switch port as a trunk port to allow multiple VLANs.

    Why it's wrong here

    Dynamic VLAN assignment typically assigns a single VLAN to an access port. The port does not need to be a trunk; in fact, it should be an access port that is dynamically moved to the assigned VLAN. Configuring a trunk port would not enable dynamic VLAN assignment and could introduce security risks by allowing multiple VLANs on the port.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.