CCNP Security Practice Question
A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?
⚠ Common exam trap
Many candidates confuse the switch that enforces port access with the server that validates credentials, which leads candidates to select the authentication server role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authenticator
In 802.1X, the three roles are supplicant, authenticator, and authentication server. The access-layer switch controls the physical port and relays EAP messages between the endpoint and Cisco ISE, so it functions as the authenticator. It also enforces the authorization result, such as a dynamic VLAN or downloadable ACL, which satisfies the requirement that the endpoint be validated before Layer 2 access is granted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication server
Why it's wrong here
The authentication server validates credentials and returns authorization attributes, and in this design that role is fulfilled by Cisco ISE, not by the access switch. While the switch forwards RADIUS requests, it does not itself make the final authentication decision. Assigning the authentication server role to the switch would misrepresent how 802.1X separates enforcement from credential validation.
- ✗
RADIUS proxy
Why it's wrong here
A RADIUS proxy forwards RADIUS messages between clients and servers, often for realm routing or policy mediation. Cisco 802.1X designs do not require the access switch to function as a proxy; it is a native RADIUS client that originates Access-Request messages. This role is a general AAA concept and not one of the three defined 802.1X roles, so it does not apply here.
- ✓
Authenticator
Why this is correct
The switch acts as the authenticator, controlling access to the port based on the outcome of EAP exchanges with the endpoint and RADIUS decisions from Cisco ISE. It relays EAP frames between the supplicant and authentication server, enforces port authorization state, and applies VLAN or ACL results. This matches the requirement that endpoints be authenticated before any Layer 2 connectivity is granted.
- ✗
Supplicant
Why it's wrong here
The supplicant is the endpoint software (for example, Cisco Secure Client) that responds to EAP identity requests and presents credentials. In this scenario the endpoint is the device being validated, not the switch enforcing policy. A switch does not run supplicant software to authenticate users on behalf of endpoints, so this role does not fit the access-layer enforcement requirement.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.