Courseiva
hardMultiple Choice

CCNP Practice Question: An enterprise network uses 802.1X for wired access

An enterprise network uses 802.1X for wired access. The authentication server is a Cisco ISE. Recently, some Windows 10 clients fail to authenticate, while others succeed. The engineer checks the switch configuration and finds 'authentication port-control auto' and 'dot1x pae authenticator' are configured. The failing clients show 'EAP failure' in the logs. The engineer suspects a mismatch in EAP method. Which EAP method is most likely causing the issue if the ISE is configured to require EAP-TLS but the Windows clients are configured for PEAP-MSCHAPv2?

⚠ Common exam trap

Cisco often tests the concept that EAP-TLS is the only EAP method that requires a client certificate by default, and candidates may confuse it with PEAP or EAP-FAST, which do not require client certificates for the inner authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EAP-TLS requires a client certificate, which the Windows clients do not have.

EAP-TLS requires a client-side certificate for authentication. If the ISE is configured to require EAP-TLS but the Windows 10 clients are configured for PEAP-MSCHAPv2, the clients will not present a certificate, causing the ISE to send an EAP failure. This mismatch in EAP method explains why only clients without the proper certificate configuration fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EAP-TLS requires a client certificate, which the Windows clients do not have.

    Why this is correct

    EAP-TLS is a certificate-based mutual authentication method: the server presents a certificate and the client must also present a valid client certificate. Since the Windows clients have not been issued client certificates, the client cannot complete the TLS handshake, so authentication fails despite the server being configured for EAP-TLS. This is the root cause described in the scenario.

  • ✗

    EAP-FAST requires a PAC file that the Windows clients do not have.

    Why it's wrong here

    EAP-FAST does rely on a Protected Access Credential (PAC), but it is not implicated in this failure. The scenario explicitly contrasts EAP-TLS with PEAP-MSCHAPv2, and neither the server nor the clients are configured for EAP-FAST. Moreover, PACs can be dynamically provisioned or manually distributed, so a missing PAC is not the reason authentication fails here.

  • ✗

    LEAP uses a shared secret that is not configured on the clients.

    Why it's wrong here

    LEAP (Lightweight Extensible Authentication Protocol) uses a username/password credential pair, not a pre-shared secret, and it is a Cisco-proprietary method that predates WPA2. The scenario never mentions LEAP, and the failure involves a certificate mismatch, not a shared-secret configuration problem. Therefore, this option is incorrect because LEAP is not the protocol in use.

  • ✗

    EAP-MD5 does not support mutual authentication, causing the failure.

    Why it's wrong here

    EAP-MD5 is an older EAP method that performs only one-way authentication (the server authenticates the user) and does not support mutual authentication, which is a known weakness. However, the scenario is about a client/server certificate mismatch between EAP-TLS and PEAP, and neither the clients nor the server are configured to use EAP-MD5. Thus, while the statement about EAP-MD5 is technically true, it does not explain the failure in this scenario.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.