Courseiva
Security →mediumMultiple Select

350-401 Security Practice Question

A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)

⚠ Common exam trap

Many candidates confuse a guest VLAN, which serves non-supplicant devices, with a restricted failure VLAN, which isolates devices that actively fail authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.

Placing failed authentications into a restricted VLAN is accomplished with the authentication event fail action authorize vlan command, which defines failure handling. Supporting an IP phone and a PC on one port with independent authentication requires multi-domain authentication, which creates separate voice and data sessions. Together these two features meet both design requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.

    Why this is correct

    The authentication event fail action authorize vlan command on the switch port directs hosts that fail 802.1X authentication into a specified restricted VLAN. This exactly matches the requirement to isolate failed devices. It is the correct IOS configuration to define failure handling behavior for the port and is essential for the design described.

  • ✓

    Enable 802.1X multi-domain authentication on the port so the phone and PC authenticate independently.

    Why this is correct

    Multi-domain authentication allows a single switch port to host both a voice domain for the IP phone and a data domain for the attached PC, each authenticating separately. This satisfies the requirement that the phone authenticate before the PC. It is the correct feature to support both devices on one port with independent 802.1X sessions.

  • ✗

    Enable port security with sticky MAC addresses on the access port.

    Why it's wrong here

    Port security limits the number of MAC addresses on a port but does not perform 802.1X authentication or VLAN assignment based on authentication results. It cannot place failed devices into a restricted VLAN or authenticate a phone before a PC. While it can complement 802.1X, it does not fulfill either stated requirement on its own.

  • ✗

    Configure a guest VLAN on the switch port for hosts that do not support 802.1X.

    Why it's wrong here

    A guest VLAN provides limited access for non-supplicant devices, but the requirement is specifically to place authentication failures into a restricted VLAN. Guest and restricted VLANs serve different purposes. Using a guest VLAN would not satisfy the failed-authentication scenario, so it does not meet the stated design requirement even though it is a valid 802.1X feature.

  • ✗

    Configure MAC Authentication Bypass (MAB) as the primary authentication method instead of 802.1X.

    Why it's wrong here

    MAB authenticates devices by MAC address and is typically used as a fallback for devices that cannot run a supplicant. Using MAB as the primary method would not authenticate the IP phone or PC via 802.1X credentials as required. It does not provide the independent per-device authentication the design demands, so it is not the correct choice.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.