mediumMultiple Choice
CCNP Practice Question: Consider the following configuration on a Cisco…
Consider the following configuration on a Cisco IOS-XE switch:
interface GigabitEthernet1/0/1 switchport mode access
authentication port-control auto dot1x pae authenticator dot1x timeout tx-period 5
spanning-tree portfast
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between authenticator and supplicant roles, and the trap here is that candidates confuse `dot1x pae authenticator` with a supplicant configuration or assume that `spanning-tree portfast` overrides the unauthorized state, leading them to pick Option A or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch will act as an 802.1X authenticator and the port will be unauthorized until a successful authentication.
The configuration enables 802.1X authentication on the port with `authentication port-control auto`, making the port start in the unauthorized state. The `dot1x pae authenticator` command configures the switch as the authenticator (not a supplicant). The `spanning-tree portfast` command allows the port to transition to forwarding quickly after authentication succeeds, but until then, the port remains unauthorized and blocks traffic. Option B correctly states that the switch acts as an authenticator and the port is unauthorized until successful authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The port will immediately transition to forwarding state and then wait for authentication.
Why it's wrong here
PortFast accelerates Spanning Tree Protocol convergence by moving the port into the forwarding state, but it does not bypass 802.1X authentication. With 'authentication port-control auto', the controlled port remains in the unauthorized state, blocking all user traffic until the supplicant completes EAP authentication. The port may be STP-forwarding, but the 802.1X controlled port will not forward data frames until successful authentication, so this statement conflates two independent mechanisms.
- ✓
The switch will act as an 802.1X authenticator and the port will be unauthorized until a successful authentication.
Why this is correct
The 'dot1x pae authenticator' command configures the switch port to operate as the 802.1X authenticator, meaning it initiates and manages EAP exchanges with the connected client (supplicant). The 'authentication port-control auto' setting explicitly places the port in the unauthorized state initially, allowing only EAPOL traffic to flow. Only after the client successfully authenticates against the configured authentication method (e.g., RADIUS) does the controlled port transition to the authorized state and forward normal data traffic.
- ✗
The port will be placed in a VLAN assigned by the RADIUS server after authentication.
Why it's wrong here
Dynamic VLAN assignment by the RADIUS server requires a configured RADIUS server, a AAA method list, and the RADIUS server to return vendor-specific attributes such as Tunnel-Private-Group-ID to change the port VLAN. The given configuration fragment shows none of these elements, so there is no basis to conclude that a RADIUS-assigned VLAN will be used. Without such attributes or server configuration, the port would remain in its locally configured access VLAN after authentication, making this option unsupported by the evidence shown.
- ✗
The switch will act as a supplicant and respond to EAP requests from an upstream authenticator.
Why it's wrong here
The switch configured with 'dot1x pae authenticator' is explicitly assigned the authenticator role, not the supplicant role. A supplicant would require 'dot1x pae supplicant', and would send EAPOL-Start and respond to EAP-Request/Identity from an upstream authenticator, such as when a switch is connected to a larger network and must prove itself. Since the configuration clearly sets the switch as the authenticator, it is responsible for authenticating downstream devices rather than responding to authentication requests from upstream devices, so this option contradicts the command's purpose.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.