Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The RADIUS server is reachable at 10.10.10.5 using the key 'Cisco123'. The switch must dynamically assign VLANs based on the RADIUS attributes returned. Which configuration is required on the switch to enable dynamic VLAN assignment?

⚠ Common exam trap

The trap here is assuming that authentication alone is sufficient for dynamic VLAN assignment, but authorization is required to process and apply the RADIUS attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control

For dynamic VLAN assignment with 802.1X, the switch must authenticate the user and authorize the session to receive VLAN attributes from the RADIUS server. The 'aaa authorization network default group radius' command enables the switch to process these attributes. Without it, the switch will not apply the VLAN, even if authentication succeeds. The RADIUS server and global 802.1X configuration are also required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aaa new-model aaa authentication dot1x default group radius aaa accounting network default start-stop group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control

    Why it's wrong here

    This configuration uses accounting instead of authorization. Accounting records user activity but does not process authorization attributes needed for dynamic VLAN assignment. The switch would authenticate users and send accounting records, but it would not apply any VLAN from the RADIUS server. Authorization must be explicitly configured to enable the switch to accept and use the VLAN attributes.

  • ✓

    aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control

    Why this is correct

    This configuration includes 'aaa authorization network default group radius', which is necessary for the switch to authorize the user and apply VLAN assignment from the RADIUS server. The authentication command verifies credentials, while authorization processes the returned attributes such as tunnel-type, tunnel-medium, and tunnel-private-group-id to assign the VLAN. The RADIUS server and dot1x system-auth-control are also correctly configured.

  • ✗

    aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 no dot1x system-auth-control

    Why it's wrong here

    The command 'no dot1x system-auth-control' disables 802.1X globally on the switch, which prevents any port from performing 802.1X authentication. Even with correct AAA and RADIUS configuration, without global 802.1X enabled, the switch will not initiate authentication, and dynamic VLAN assignment cannot occur. The 'dot1x system-auth-control' command must be enabled.

  • ✗

    aaa new-model aaa authentication dot1x default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control

    Why it's wrong here

    This configuration enables 802.1X authentication and RADIUS, but it does not enable the switch to accept VLAN assignment from the RADIUS server. The command 'aaa authorization network default group radius' is missing, which is required to process the tunnel attributes that carry VLAN information. Without authorization, the switch will authenticate the user but will not apply any dynamic VLAN.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.