mediumMultiple Select
CCNP Practice Question: Which two statements about 802.1X port states and…
Which two statements about 802.1X port states and access control are true? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Before authentication, the switch port is in the unauthorized state and only allows EAPOL frames.
Option A is correct because in 802.1X the controlled port starts in the unauthorized state, and only EAPOL (Ethernet type 0x888E) frames are permitted so the supplicant can negotiate with the authenticator; all other traffic is dropped. Option B is correct because once the supplicant successfully authenticates via EAP over EAPOL and the RADIUS server returns Access-Accept, the authenticator moves the controlled port to the authorized state and normal data traffic is allowed. Option C is wrong because multi-auth mode authorizes each device individually, so the port is not opened for all devices after just the first successful authentication. Option D is wrong because authentication is triggered by EAPOL-Start (or EAPOL frames), not by ordinary data traffic, and the port stays unauthorized until authentication succeeds. Option E is wrong because 802.1X is a Layer 2 port-based access control mechanism applied to switch ports, not to Layer 3 routed interfaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Before authentication, the switch port is in the unauthorized state and only allows EAPOL frames.
Why this is correct
Before authentication, the port stays in the uncontrolled (unauthorized) state, permitting only EAPOL traffic between supplicant and authenticator. This satisfies the stem's access-control constraint: no ordinary data frames pass until the authentication server authorises the supplicant, after which the port transitions to the controlled, authorised state.
- ✓
After successful 802.1X authentication, the port transitions to the authorized state and all traffic is permitted.
Why this is correct
After successful 802.1X authentication, the switch port moves from the unauthorised to the authorised state, permitting normal traffic for that supplicant. This satisfies the stem's requirement to identify true statements about port states: authorisation is granted per port following successful EAP exchange with the RADIUS server, not before.
- ✗
In multi-auth mode, the port becomes authorized for all devices once the first device authenticates successfully.
Why it's wrong here
Multi-auth authorises each device independently, so later devices must authenticate separately rather than inheriting the first device's authorisation. It is tempting because it sounds like multi-domain mode, where one successful authentication does authorise the port for all attached devices.
- ✗
The port remains in the unauthorized state until the client sends data traffic.
Why it's wrong here
The port stays unauthorised until the supplicant responds to EAP identity requests, not until data traffic arrives; data frames are blocked while unauthorised. It is tempting because traffic often triggers authentication, but the actual trigger is the EAP exchange, not the data itself.
- ✗
802.1X can be configured on a Layer 3 interface to authenticate users before routing.
Why it's wrong here
802.1X operates at Layer 2 on switch ports, authenticating before any Layer 3 addressing or routing occurs; it cannot be configured on a Layer 3 interface for that purpose. It is tempting because it sounds like a routed access-control method, but that role belongs to other mechanisms.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.