350-401 Security Practice Question
A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)
⚠ Common exam trap
Many candidates confuse a guest VLAN, which serves non-supplicant devices, with a restricted failure VLAN, which isolates devices that actively fail authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.
Placing failed authentications into a restricted VLAN is accomplished with the authentication event fail action authorize vlan command, which defines failure handling. Supporting an IP phone and a PC on one port with independent authentication requires multi-domain authentication, which creates separate voice and data sessions. Together these two features meet both design requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.
Why this is correct
The authentication event fail action authorize vlan command on the switch port directs hosts that fail 802.1X authentication into a specified restricted VLAN. This exactly matches the requirement to isolate failed devices. It is the correct IOS configuration to define failure handling behavior for the port and is essential for the design described.
- ✓
Enable 802.1X multi-domain authentication on the port so the phone and PC authenticate independently.
Why this is correct
Multi-domain authentication allows a single switch port to host both a voice domain for the IP phone and a data domain for the attached PC, each authenticating separately. This satisfies the requirement that the phone authenticate before the PC. It is the correct feature to support both devices on one port with independent 802.1X sessions.
- ✗
Enable port security with sticky MAC addresses on the access port.
Why it's wrong here
Port security limits the number of MAC addresses on a port but does not perform 802.1X authentication or VLAN assignment based on authentication results. It cannot place failed devices into a restricted VLAN or authenticate a phone before a PC. While it can complement 802.1X, it does not fulfill either stated requirement on its own.
- ✗
Configure a guest VLAN on the switch port for hosts that do not support 802.1X.
Why it's wrong here
A guest VLAN provides limited access for non-supplicant devices, but the requirement is specifically to place authentication failures into a restricted VLAN. Guest and restricted VLANs serve different purposes. Using a guest VLAN would not satisfy the failed-authentication scenario, so it does not meet the stated design requirement even though it is a valid 802.1X feature.
- ✗
Configure MAC Authentication Bypass (MAB) as the primary authentication method instead of 802.1X.
Why it's wrong here
MAB authenticates devices by MAC address and is typically used as a fallback for devices that cannot run a supplicant. Using MAB as the primary method would not authenticate the IP phone or PC via 802.1X credentials as required. It does not provide the independent per-device authentication the design demands, so it is not the correct choice.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.