Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?

⚠ Common exam trap

The trap here is focusing on switch-side 802.1X host modes or RADIUS secrets while overlooking that MAB success hinges on exact MAC address formatting in the ISE endpoint database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.

MAB authentication depends on ISE matching the MAC address sent in the RADIUS request to an endpoint record. If the stored MAC format differs from the format in the Calling-Station-Id attribute, the endpoint is not matched to its identity group and authorization fails. Ensuring consistent MAC formatting resolves the rejection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.

    Why this is correct

    ISE matches MAB requests against endpoint MAC addresses in its database using a specific format. If the endpoint was added with a different delimiter or case than what the switch sends in the Calling-Station-Id, ISE will not match the identity group and will reject the request, causing the unauthorized state.

  • ✗

    The switch port is configured with authentication host-mode multi-domain instead of multi-auth.

    Why it's wrong here

    Multi-domain mode is designed for a single voice device and a single data device on the same port, which can still support MAB for the printer. Changing to multi-auth would allow multiple data devices but does not explain why a valid MAC in the correct ISE identity group is rejected, so this is not the likely cause.

  • ✗

    The RADIUS shared secret on the switch does not match the one configured for the switch in Cisco ISE.

    Why it's wrong here

    A RADIUS shared secret mismatch would prevent authentication requests from being processed at all, typically resulting in no response or an authentication failure for all methods, not a MAB-specific rejection. Since the switch shows MAB as the method, the request is reaching ISE, so the shared secret is likely correct.

  • ✗

    The switch is configured with dot1x pae authenticator on the port instead of pae supplicant.

    Why it's wrong here

    The authenticator role is correct for a switch port performing 802.1X and MAB; supplicant mode is for endpoints. Configuring the switch as a supplicant would be incorrect for this scenario and would not cause a MAB request to be rejected by ISE when the MAC is valid.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.