Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer needs to configure a switch port to authenticate end hosts against a RADIUS server. The requirement is that if the RADIUS server becomes unreachable, the port should place the host on a guest VLAN instead of shutting down. Which command must be added to the interface configuration?

⚠ Common exam trap

It's easy for candidates to confuse authentication failure actions with server-dead actions, where a server-dead event requires a distinct command to handle unreachable RADIUS servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

authentication event server dead action authorize vlan 10

When a RADIUS server becomes unreachable, the switch can be configured to authorize the port into a specific VLAN rather than shutting it down. The 'authentication event server dead action authorize vlan' command implements this by defining the VLAN to assign. The other options either handle different authentication events or alter port behaviour in ways that do not match the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    authentication host-mode multi-auth

    Why it's wrong here

    This command allows multiple hosts to authenticate independently on a single port. It does not control fallback behaviour when the RADIUS server is down. While it can be useful in some deployments, it does nothing to satisfy the requirement of redirecting hosts to a guest VLAN upon server failure, and thus is incorrect for this scenario.

  • ✓

    authentication event server dead action authorize vlan 10

    Why this is correct

    This command instructs the switch to place the port into the specified guest VLAN when the RADIUS server fails to respond to authentication requests, satisfying the requirement to avoid shutting the port down. It is part of Cisco IOS 802.1X authentication event configuration and directly addresses the server-dead condition by authorizing a fallback VLAN rather than a critical VLAN.

  • ✗

    authentication event fail action authorize vlan 10

    Why it's wrong here

    This command defines the action when authentication fails due to invalid credentials, not when the RADIUS server is unreachable. It would place the host into VLAN 10 if the user enters wrong credentials, which is not the desired behaviour for server failure. The requirement specifically mentions server unreachability, so this option misapplies the authentication event category.

  • ✗

    authentication open

    Why it's wrong here

    This command enables open authentication mode, allowing devices to access the network without authentication. It does not provide a guest VLAN fallback when the RADIUS server is unreachable; instead, it bypasses authentication entirely. The scenario requires authenticated access with a fallback, so this option does not meet the requirement and is therefore wrong.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.