350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The RADIUS server is reachable at 10.10.10.5 using the key 'Cisco123'. The switch must dynamically assign VLANs based on the RADIUS attributes returned. Which configuration is required on the switch to enable dynamic VLAN assignment?
⚠ Common exam trap
The trap here is assuming that authentication alone is sufficient for dynamic VLAN assignment, but authorization is required to process and apply the RADIUS attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
For dynamic VLAN assignment with 802.1X, the switch must authenticate the user and authorize the session to receive VLAN attributes from the RADIUS server. The 'aaa authorization network default group radius' command enables the switch to process these attributes. Without it, the switch will not apply the VLAN, even if authentication succeeds. The RADIUS server and global 802.1X configuration are also required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa new-model aaa authentication dot1x default group radius aaa accounting network default start-stop group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
Why it's wrong here
This configuration uses accounting instead of authorization. Accounting records user activity but does not process authorization attributes needed for dynamic VLAN assignment. The switch would authenticate users and send accounting records, but it would not apply any VLAN from the RADIUS server. Authorization must be explicitly configured to enable the switch to accept and use the VLAN attributes.
- ✓
aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
Why this is correct
This configuration includes 'aaa authorization network default group radius', which is necessary for the switch to authorize the user and apply VLAN assignment from the RADIUS server. The authentication command verifies credentials, while authorization processes the returned attributes such as tunnel-type, tunnel-medium, and tunnel-private-group-id to assign the VLAN. The RADIUS server and dot1x system-auth-control are also correctly configured.
- ✗
aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 no dot1x system-auth-control
Why it's wrong here
The command 'no dot1x system-auth-control' disables 802.1X globally on the switch, which prevents any port from performing 802.1X authentication. Even with correct AAA and RADIUS configuration, without global 802.1X enabled, the switch will not initiate authentication, and dynamic VLAN assignment cannot occur. The 'dot1x system-auth-control' command must be enabled.
- ✗
aaa new-model aaa authentication dot1x default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
Why it's wrong here
This configuration enables 802.1X authentication and RADIUS, but it does not enable the switch to accept VLAN assignment from the RADIUS server. The command 'aaa authorization network default group radius' is missing, which is required to process the tunnel attributes that carry VLAN information. Without authorization, the switch will authenticate the user but will not apply any dynamic VLAN.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.