Courseiva
Infrastructure →hardMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco Catalyst switch to support 802.1X authentication for wired users. The company requires that if the RADIUS server becomes unreachable, devices on a critical VLAN should be allowed access to the network without authentication. Which feature should be configured on the switch to meet this requirement?

⚠ Common exam trap

A common mix-up: candidates confuse Inaccessible Authentication Bypass with Critical VLAN; while related, IAB is the feature that enables the bypass behavior when the server is down, whereas Critical VLAN is the VLAN assignment used by IAB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inaccessible Authentication Bypass

Inaccessible Authentication Bypass (IAB) is designed to handle the exact situation where the RADIUS server becomes unreachable. When enabled, the switch places the port into a critical VLAN, allowing devices to gain network access without authentication. This feature is essential for maintaining connectivity for critical devices during an authentication server outage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Inaccessible Authentication Bypass

    Why this is correct

    Inaccessible Authentication Bypass (IAB) is a Cisco feature that allows a port to be authorized and placed into a configurable critical VLAN when the RADIUS server is unreachable. This ensures that critical devices can still access the network without authentication during a server outage, meeting the requirement exactly.

  • ✗

    Guest VLAN

    Why it's wrong here

    Guest VLAN is used to provide limited network access to devices that do not support 802.1X or fail authentication. It does not specifically address the scenario where the RADIUS server is unreachable; it is triggered by authentication failure or lack of supplicant. The requirement is for server unreachability, so Guest VLAN is not the correct feature.

  • ✗

    Critical VLAN

    Why it's wrong here

    Critical VLAN is an 802.1X feature that assigns authenticated ports to a specified VLAN when the RADIUS server is unreachable. However, it does not allow access without authentication; it places the port in a restricted VLAN that typically has limited access. The requirement is to allow access to a critical VLAN, which is exactly what Critical VLAN does, but the wording 'without authentication' might imply full access, which is not the case.

  • ✗

    MAC Authentication Bypass

    Why it's wrong here

    MAC Authentication Bypass (MAB) is used for devices that cannot perform 802.1X, such as printers. It uses the device's MAC address as the username and password for RADIUS authentication. MAB does not bypass authentication when the RADIUS server is down; it still requires the server to be reachable to authenticate the MAC address.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.