Courseiva
mediumMultiple Choice

CCNP Practice Question: Is configuring a Cisco switch for 802.1X…

A network engineer is configuring a Cisco switch for 802.1X port-based authentication. The switch is configured with a RADIUS server for authentication. The engineer wants to allow devices that fail 802.1X authentication to still access a limited guest VLAN. The engineer configures 'authentication port-control auto' and 'authentication host-mode multi-host' on the interface. However, when a non-802.1X-capable device is connected, the port remains in the unauthorized state and does not fall into the guest VLAN. What is missing?

⚠ Common exam trap

Cisco often tests the distinction between the authentication method (RADIUS configuration) and the fallback mechanism (guest VLAN), leading candidates to assume that missing AAA commands are the root cause when the actual missing piece is the explicit guest VLAN assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The interface needs the 'authentication guest-vlan <vlan-id>' command to specify the VLAN for non-802.1X devices.

The 'authentication guest-vlan <vlan-id>' command is missing. This command explicitly defines the VLAN to which the port will assign devices that fail 802.1X authentication or are non-802.1X-capable. Without it, the switch has no configured fallback VLAN, so the port remains in the unauthorized state even with 'authentication port-control auto' and 'authentication host-mode multi-host' configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The interface needs the 'authentication guest-vlan <vlan-id>' command to specify the VLAN for non-802.1X devices.

    Why this is correct

    The interface-level command 'authentication guest-vlan <vlan-id>' is required to define a fallback VLAN for devices that do not respond to 802.1X or whose authentication times out. Without this command, a non-802.1X capable device will be denied access or left in an unauthorized state, because the switch has no VLAN to assign it. The guest VLAN is a per-interface configuration, separate from global AAA commands, and it must reference an existing VLAN on the switch.

  • ✗

    The switch must have 'aaa authentication dot1x default group radius' configured globally.

    Why it's wrong here

    This global configuration is already assumed to be in place in the scenario, as the switch is attempting 802.1X authentication and the failure occurs at the interface level. The command 'aaa authentication dot1x default group radius' only specifies the authentication method and server; it has no role in assigning a VLAN to a failed or unauthenticated host. The missing piece is the interface-specific guest VLAN definition, not a global authentication rule.

  • ✗

    The 'authentication host-mode multi-host' command should be replaced with 'authentication host-mode multi-domain' to support guest VLAN.

    Why it's wrong here

    Replacing 'multi-host' with 'multi-domain' would change how multiple devices are authenticated on the port, but it does not affect whether a guest VLAN can be used. 'Multi-domain' restricts the port to one voice and one data device, while 'multi-host' allows any number of devices after a single successful authentication. Both host modes support a guest VLAN; the actual problem is that no guest VLAN has been configured with the 'authentication guest-vlan' command.

  • ✗

    The port must be configured as a trunk port to allow the guest VLAN.

    Why it's wrong here

    The guest VLAN is a single, untagged VLAN that the switch dynamically assigns to an access port when authentication fails; it is not a trunk VLAN. Trunk ports are designed to carry multiple VLANs with tagging, which would introduce unnecessary complexity and security risk for a guest access environment. A standard access port with 'authentication guest-vlan' is sufficient, and the command works regardless of the port's trunk or access mode—but using trunk would not solve the missing VLAN definition.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.