350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco Catalyst switch to support 802.1X authentication for wired users. The company requires that if the RADIUS server becomes unreachable, devices on a critical VLAN should be allowed access to the network without authentication. Which feature should be configured on the switch to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse Inaccessible Authentication Bypass with Critical VLAN; while related, IAB is the feature that enables the bypass behavior when the server is down, whereas Critical VLAN is the VLAN assignment used by IAB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inaccessible Authentication Bypass
Inaccessible Authentication Bypass (IAB) is designed to handle the exact situation where the RADIUS server becomes unreachable. When enabled, the switch places the port into a critical VLAN, allowing devices to gain network access without authentication. This feature is essential for maintaining connectivity for critical devices during an authentication server outage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inaccessible Authentication Bypass
Why this is correct
Inaccessible Authentication Bypass (IAB) is a Cisco feature that allows a port to be authorized and placed into a configurable critical VLAN when the RADIUS server is unreachable. This ensures that critical devices can still access the network without authentication during a server outage, meeting the requirement exactly.
- ✗
Guest VLAN
Why it's wrong here
Guest VLAN is used to provide limited network access to devices that do not support 802.1X or fail authentication. It does not specifically address the scenario where the RADIUS server is unreachable; it is triggered by authentication failure or lack of supplicant. The requirement is for server unreachability, so Guest VLAN is not the correct feature.
- ✗
Critical VLAN
Why it's wrong here
Critical VLAN is an 802.1X feature that assigns authenticated ports to a specified VLAN when the RADIUS server is unreachable. However, it does not allow access without authentication; it places the port in a restricted VLAN that typically has limited access. The requirement is to allow access to a critical VLAN, which is exactly what Critical VLAN does, but the wording 'without authentication' might imply full access, which is not the case.
- ✗
MAC Authentication Bypass
Why it's wrong here
MAC Authentication Bypass (MAB) is used for devices that cannot perform 802.1X, such as printers. It uses the device's MAC address as the username and password for RADIUS authentication. MAB does not bypass authentication when the RADIUS server is down; it still requires the server to be reachable to authenticate the MAC address.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.