Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?

⚠ Common exam trap

Many candidates confuse the switch that enforces port access with the server that validates credentials, which leads candidates to select the authentication server role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authenticator

In 802.1X, the three roles are supplicant, authenticator, and authentication server. The access-layer switch controls the physical port and relays EAP messages between the endpoint and Cisco ISE, so it functions as the authenticator. It also enforces the authorization result, such as a dynamic VLAN or downloadable ACL, which satisfies the requirement that the endpoint be validated before Layer 2 access is granted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authentication server

    Why it's wrong here

    The authentication server validates credentials and returns authorization attributes, and in this design that role is fulfilled by Cisco ISE, not by the access switch. While the switch forwards RADIUS requests, it does not itself make the final authentication decision. Assigning the authentication server role to the switch would misrepresent how 802.1X separates enforcement from credential validation.

  • ✗

    RADIUS proxy

    Why it's wrong here

    A RADIUS proxy forwards RADIUS messages between clients and servers, often for realm routing or policy mediation. Cisco 802.1X designs do not require the access switch to function as a proxy; it is a native RADIUS client that originates Access-Request messages. This role is a general AAA concept and not one of the three defined 802.1X roles, so it does not apply here.

  • ✓

    Authenticator

    Why this is correct

    The switch acts as the authenticator, controlling access to the port based on the outcome of EAP exchanges with the endpoint and RADIUS decisions from Cisco ISE. It relays EAP frames between the supplicant and authentication server, enforces port authorization state, and applies VLAN or ACL results. This matches the requirement that endpoints be authenticated before any Layer 2 connectivity is granted.

  • ✗

    Supplicant

    Why it's wrong here

    The supplicant is the endpoint software (for example, Cisco Secure Client) that responds to EAP identity requests and presents credentials. In this scenario the endpoint is the device being validated, not the switch enforcing policy. A switch does not run supplicant software to authenticate users on behalf of endpoints, so this role does not fit the access-layer enforcement requirement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.