350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco IOS switch to use 802.1X authentication for endpoints connected to interface GigabitEthernet1/0/1. The engineer wants to ensure that if the RADIUS server is unreachable, the port will be placed in a restricted VLAN. Which command should be used?
⚠ Common exam trap
A common mix-up: candidates confuse the server dead event with fail or no-response events, which handle different failure conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication event server dead action authorize vlan 10
The command 'authentication event server dead action authorize vlan 10' is specifically designed to handle the case where the RADIUS server is unreachable, placing the port into VLAN 10 as a fallback. This ensures that endpoints can still access limited network resources according to policy when the authentication server is down.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
authentication host-mode multi-auth
Why it's wrong here
This command sets the host mode to multi-auth, allowing multiple devices to authenticate on the same port. It does not provide any fallback authorization when the RADIUS server is dead. Therefore, it is unrelated to the requirement of placing the port in a restricted VLAN upon server failure.
- ✗
authentication event fail action authorize vlan 10
Why it's wrong here
This command defines the action when authentication fails, not when the server is unreachable. It would authorize the port into VLAN 10 if the client fails authentication, which is different from the server being dead. Using this command would not meet the requirement of handling server unavailability.
- ✗
authentication event no-response action authorize vlan 10
Why it's wrong here
This command is used when the client does not respond to authentication requests, not when the server is dead. It would authorize the port into VLAN 10 if the supplicant is unresponsive. While it provides a fallback, it does not address the specific scenario of the RADIUS server being unreachable.
- ✓
authentication event server dead action authorize vlan 10
Why this is correct
This command specifies that if the RADIUS server becomes unreachable, the port will be authorized into VLAN 10, providing restricted access. It is used within 802.1X configuration to define fallback behavior when the authentication server is dead, ensuring that endpoints can still gain limited network access according to policy.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.