Courseiva
SecurityhardMultiple SelectObjective-mapped

350-601 Security Practice Question

Which THREE of the following must be enabled to implement 802.1X authentication with MAB fallback on a Cisco Nexus switch for a mixed environment of 802.1X-capable and non-802.1X endpoints? (Choose three.)

⚠ Common exam trap

Cisco often tests the misconception that MACsec or VLAN ACLs are prerequisites for 802.1X with MAB, when in fact they are optional features that can be layered on top of the authentication process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AAA authentication with a RADIUS server

802.1X authentication requires AAA to communicate with a RADIUS server. The RADIUS server validates the credentials (EAP over RADIUS) and returns an Accept or Reject, which the switch uses to authorize the port. Without AAA and a RADIUS server, the switch has no external authentication authority to process 802.1X requests or MAB fallback.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • MACsec encryption on the port

    Why it's wrong here

    MACsec is optional and not required for 802.1X/MAB.

  • AAA authentication with a RADIUS server

    Why this is correct

    AAA is required to authenticate users and devices.

  • A RADIUS server configured with the MAC addresses of non-802.1X devices

    Why this is correct

    RADIUS server must have the MAC addresses for MAB authentication.

  • A VLAN ACL to redirect traffic

    Why it's wrong here

    VLAN ACLs are not part of 802.1X/MAB.

  • 802.1X globally enabled on the switch

    Why this is correct

    Global 802.1X is required.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-601 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.