Courseiva
mediumMultiple Select

CCNP Practice Question: Which two statements about 802.1X port states and…

Which two statements about 802.1X port states and access control are true? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Before authentication, the switch port is in the unauthorized state and only allows EAPOL frames.

Option A is correct because in 802.1X the controlled port starts in the unauthorized state, and only EAPOL (Ethernet type 0x888E) frames are permitted so the supplicant can negotiate with the authenticator; all other traffic is dropped. Option B is correct because once the supplicant successfully authenticates via EAP over EAPOL and the RADIUS server returns Access-Accept, the authenticator moves the controlled port to the authorized state and normal data traffic is allowed. Option C is wrong because multi-auth mode authorizes each device individually, so the port is not opened for all devices after just the first successful authentication. Option D is wrong because authentication is triggered by EAPOL-Start (or EAPOL frames), not by ordinary data traffic, and the port stays unauthorized until authentication succeeds. Option E is wrong because 802.1X is a Layer 2 port-based access control mechanism applied to switch ports, not to Layer 3 routed interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Before authentication, the switch port is in the unauthorized state and only allows EAPOL frames.

    Why this is correct

    Before authentication, the port stays in the uncontrolled (unauthorized) state, permitting only EAPOL traffic between supplicant and authenticator. This satisfies the stem's access-control constraint: no ordinary data frames pass until the authentication server authorises the supplicant, after which the port transitions to the controlled, authorised state.

  • ✓

    After successful 802.1X authentication, the port transitions to the authorized state and all traffic is permitted.

    Why this is correct

    After successful 802.1X authentication, the switch port moves from the unauthorised to the authorised state, permitting normal traffic for that supplicant. This satisfies the stem's requirement to identify true statements about port states: authorisation is granted per port following successful EAP exchange with the RADIUS server, not before.

  • ✗

    In multi-auth mode, the port becomes authorized for all devices once the first device authenticates successfully.

    Why it's wrong here

    Multi-auth authorises each device independently, so later devices must authenticate separately rather than inheriting the first device's authorisation. It is tempting because it sounds like multi-domain mode, where one successful authentication does authorise the port for all attached devices.

  • ✗

    The port remains in the unauthorized state until the client sends data traffic.

    Why it's wrong here

    The port stays unauthorised until the supplicant responds to EAP identity requests, not until data traffic arrives; data frames are blocked while unauthorised. It is tempting because traffic often triggers authentication, but the actual trigger is the EAP exchange, not the data itself.

  • ✗

    802.1X can be configured on a Layer 3 interface to authenticate users before routing.

    Why it's wrong here

    802.1X operates at Layer 2 on switch ports, authenticating before any Layer 3 addressing or routing occurs; it cannot be configured on a Layer 3 interface for that purpose. It is tempting because it sounds like a routed access-control method, but that role belongs to other mechanisms.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.