300-410 Infrastructure Security Practice Question
A network engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The engineer wants to ensure that if the RADIUS server is unavailable, the switch will place the port in a restricted VLAN for guest access. Which command must be configured on the switch port?
⚠ Common exam trap
Many exam-takers confuse the 'server dead' event with 'no-response' or 'fail' events, which trigger under different conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication event server dead action authorize vlan 100
The correct command to place a port in a restricted VLAN when the RADIUS server is dead is 'authentication event server dead action authorize vlan 100'. This event is triggered when the switch determines the server is unresponsive after multiple retries. The 'fail' event is for authentication failures, and 'no-response' is for individual request timeouts, not the server being declared dead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
authentication event no-response action authorize vlan 100
Why it's wrong here
This command authorizes the port into VLAN 100 when there is no response from the authentication server. While similar to server dead, 'no-response' typically applies when the server does not respond to a request, but 'server dead' is the specific event for when the server is considered dead after multiple attempts. The scenario explicitly mentions server unavailable, which is best matched by 'server dead'.
- ✓
authentication event server dead action authorize vlan 100
Why this is correct
This command configures the switch to authorize the port into VLAN 100 when the RADIUS server is detected as dead. This provides a fallback mechanism for guest access when the authentication server is unreachable, exactly as required. The VLAN must be configured and allowed on the port.
- ✗
authentication event fail action authorize vlan 100
Why it's wrong here
This command authorizes the port into VLAN 100 when authentication fails (e.g., wrong credentials), not when the server is dead. The scenario requires fallback when the RADIUS server is unavailable, so this command does not meet the requirement.
- ✗
authentication fallback vlan 100
Why it's wrong here
This is not a valid Cisco IOS command for 802.1X fallback. The correct commands use the 'authentication event' syntax with specific actions. This option is a distractor that might seem plausible but is not recognized by the switch.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.