CCNP Security Practice Question
An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?
⚠ Common exam trap
Cisco often tests the distinction between the 'dot1x pae authenticator' command and the 'authentication port-control auto' command, leading candidates to mistakenly think the PAE command alone enables 802.1X, when in fact both are required for full functionality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication port-control auto
'authentication port-control auto' is the required interface command to enable 802.1X authentication on a switch port. This command sets the port to initiate the authentication process, placing it in the unauthorized state until the client successfully authenticates via the RADIUS server (Cisco ISE). Without this command, the port will not enforce 802.1X.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dot1x pae authenticator
Why it's wrong here
The command sets the Port Access Entity (PAE) role to authenticator, which is necessary for the switch to act as the 802.1X authenticator, but it does not actually enable port-based authentication on the interface. Without 'authentication port-control auto', the port remains in its default state (force-authorized), so the command alone does not enforce 802.1X. It is a prerequisite, not the enabling command.
- ✓
authentication port-control auto
Why this is correct
This command sets the port's authentication mode to auto, meaning the port will be unauthorized until the client successfully authenticates via 802.1X. It triggers the authentication process and is the required command to enable 802.1X on an interface. This is the correct answer because it directly controls the port's state based on authentication.
- ✗
authentication port-control force-authorized
Why it's wrong here
This command disables 802.1X on the port by forcing it to the authorized state without requiring any authentication. All traffic is allowed without checking credentials, which defeats the purpose of 802.1X. It is the default for ports that do not have authentication configured, making it the opposite of what is needed.
- ✗
authentication port-control force-unauthorized
Why it's wrong here
This command forces the port to an unauthorized state, blocking all traffic regardless of authentication. While it does restrict access, it does not allow for any authentication process to succeed, so it cannot be used to implement 802.1X. It would shut down the port completely, not provide the dynamic authentication behavior required.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.