350-401 Infrastructure Practice Question
A network administrator needs to configure a Cisco IOS switch to authenticate users against a RADIUS server before granting access to a switchport. The requirement is that if the RADIUS server becomes unreachable, the port should fall back to the configured access VLAN and not shut down. Which set of commands accomplishes this?
⚠ Common exam trap
The trap here is assuming that enabling 802.1X with port-control auto alone provides fallback behavior, when a server-dead action must be explicitly configured to authorize the port into an access VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication host-mode multi-auth authentication event server dead action authorize vlan 10
To authenticate users against RADIUS and fall back to a specific access VLAN when the server is unreachable, the switch needs 802.1X enabled globally, RADIUS as the authentication method, port-control auto on the interface, and the authentication event server dead action authorize vlan command. That command keeps the port usable in the designated VLAN during server outages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication host-mode multi-auth authentication event server dead action authorize vlan 10
Why this is correct
This configuration enables 802.1X with RADIUS authentication, sets the port to auto mode, allows multiple authenticated hosts, and uses the authentication event server dead action authorize vlan 10 command. When the RADIUS server is unreachable, the port is placed in the specified access VLAN (10) rather than shutting down or remaining unauthorized, exactly matching the fallback requirement.
- ✗
aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto
Why it's wrong here
These commands enable 802.1X and set port-control to auto, but without authentication host-mode and an explicit critical authentication configuration, an unreachable RADIUS server causes the port to remain in the unauthorized state. The stated requirement of falling back to the access VLAN when the server is down is not satisfied by this configuration alone.
- ✗
aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication open authentication event fail action authorize vlan 20
Why it's wrong here
The authentication event fail action authorize vlan 20 command handles authentication failures by moving the port to VLAN 20, but it does not address the server-unreachable case. With authentication open, unauthenticated traffic may be allowed before authentication completes, which conflicts with the requirement to authenticate users before granting access.
- ✗
aaa new-model aaa authentication login default group radius local dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control force-authorized
Why it's wrong here
Force-authorized places the port permanently in the authorized state without any 802.1X authentication, so RADIUS is never consulted on that port. This defeats the purpose of authenticating users against the server. The fallback behavior described in the scenario is irrelevant because authentication is bypassed entirely.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.