350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The switch must place authenticated users into a specific VLAN based on the RADIUS server's response, and unauthenticated users should have no network access. Which configuration element is required on the switch to support dynamic VLAN assignment?
⚠ Common exam trap
It's easy for candidates to confuse RADIUS Change of Authorization with the initial dynamic VLAN assignment mechanism, which relies on tunnel attributes in the Access-Accept message, not on CoA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the RADIUS server to return the IETF attributes Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID, and ensure the switch interface is in access mode with 802.1X enabled.
Dynamic VLAN assignment in 802.1X requires the RADIUS server to return specific tunnel attributes that the switch interprets to place the authenticated user into a designated VLAN. The switch port must be configured for 802.1X and usually in access mode. The combination of the correct RADIUS attributes and the proper switch configuration enables the switch to move the port to the VLAN specified by the server after successful authentication, providing the required access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the switch to use MAC authentication bypass (MAB) and assign a static VLAN to the interface.
Why it's wrong here
MAC authentication bypass can authenticate devices that do not support 802.1X by using their MAC address as the username and password. However, assigning a static VLAN to the interface does not provide dynamic VLAN assignment based on the RADIUS response. While MAB can be used with dynamic VLANs, the static VLAN configuration in this option would override any dynamic assignment, so it fails the requirement.
- ✗
Configure the interface as a trunk port and allow all VLANs.
Why it's wrong here
Configuring the interface as a trunk would allow multiple VLANs but would not provide dynamic VLAN assignment based on user authentication. In 802.1X scenarios, the port typically starts in an unauthorized state and, upon successful authentication, is placed into a VLAN. A trunk configuration is not appropriate for a single user device and does not fulfill the requirement to assign a VLAN from the RADIUS response.
- ✗
Configure the switch to use RADIUS Change of Authorization (CoA) and enable dynamic VLAN assignment on the interface.
Why it's wrong here
RADIUS CoA is used to change authorization for an already authenticated session, such as reauthenticating or applying new policies. While CoA can trigger VLAN changes mid-session, the initial dynamic VLAN assignment upon authentication does not require CoA. The switch simply needs to honor the tunnel attributes returned in the initial RADIUS Access-Accept. Enabling CoA alone would not satisfy the requirement for initial VLAN placement.
- ✓
Configure the RADIUS server to return the IETF attributes Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID, and ensure the switch interface is in access mode with 802.1X enabled.
Why this is correct
For dynamic VLAN assignment, the RADIUS server must return the standard IETF attributes: Tunnel-Type set to VLAN, Tunnel-Medium-Type set to IEEE-802, and Tunnel-Private-Group-ID containing the VLAN ID or name. The switch interface must be configured for 802.1X and typically in access mode so that the port can be moved to the assigned VLAN upon authentication. This is the correct combination to meet the requirement.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.