350-401 Security Practice Question
A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?
⚠ Common exam trap
It's easy for candidates to confuse authentication protocols like EAP-TLS or MS-CHAPv2 with transport encryption mechanisms, leading to the selection of an option that secures client authentication but not the RADIUS transport.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RADIUS over TLS (RadSec)
RadSec (RADIUS over TLS) is the correct protocol to encrypt RADIUS communication between a WLC and a RADIUS server. It uses TLS to secure the entire RADIUS packet, ensuring confidentiality and integrity. Other options either refer to authentication methods or do not provide native encryption for RADIUS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS with IPsec
Why it's wrong here
While IPsec can be used to secure RADIUS traffic, it is not a native RADIUS security mechanism and is typically used for site-to-site VPNs. RadSec is the standard for encrypting RADIUS. This option is incorrect because it is not the typical or recommended approach for WLC-to-RADIUS communication.
- ✓
RADIUS over TLS (RadSec)
Why this is correct
RadSec (RADIUS over TLS) encrypts RADIUS packets using TLS, providing secure communication between the WLC and the RADIUS server. This protects credentials and attributes from eavesdropping. It is the recommended method for securing RADIUS traffic in modern deployments.
- ✗
RADIUS with MS-CHAPv2
Why it's wrong here
MS-CHAPv2 is an authentication protocol used within RADIUS, not a transport encryption method. It does not encrypt the RADIUS communication itself. This option is incorrect because it does not provide encryption for the RADIUS packets between the WLC and the server.
- ✗
RADIUS with EAP-TLS
Why it's wrong here
EAP-TLS is an authentication method used between the supplicant and the authentication server, not between the WLC and the RADIUS server. It secures the client authentication but does not encrypt the RADIUS protocol itself. This option is incorrect because it confuses the authentication method with the transport security.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.