350-401 Infrastructure Practice Question
A network engineer is configuring a switch to support 802.1X authentication for wired clients. The requirement is to authenticate users against a centralized RADIUS server and assign dynamic VLANs based on the user's role. Which command must be configured on the switch to enable 802.1X authentication globally?
⚠ Common exam trap
Watch out — candidates often confuse the global enablement command with interface-level or AAA commands that are also part of 802.1X configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dot1x system-auth-control
To enable 802.1X authentication globally on a Cisco switch, the 'dot1x system-auth-control' command must be configured. This command activates the 802.1X process and allows the switch to act as an authenticator. Other commands, such as those for RADIUS or interface-level settings, are necessary but do not globally enable 802.1X.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa authentication dot1x default group radius
Why it's wrong here
The command 'aaa authentication dot1x default group radius' specifies the authentication method list for 802.1X, directing authentication requests to a RADIUS server group. While this command is necessary for 802.1X to work with RADIUS, it does not globally enable 802.1X on the switch. It must be used in conjunction with 'dot1x system-auth-control'. Alone, it does not activate 802.1X authentication.
- ✓
dot1x system-auth-control
Why this is correct
The command 'dot1x system-auth-control' enables 802.1X authentication globally on a Cisco switch. It is a prerequisite for configuring 802.1X on individual interfaces. Without this command, 802.1X authentication will not function, even if interface-level commands are configured. This command allows the switch to act as an authenticator and communicate with the RADIUS server to authenticate supplicants.
- ✗
authentication port-control auto
Why it's wrong here
The command 'authentication port-control auto' is an interface-level command that enables 802.1X authentication on a specific port. It does not enable 802.1X globally. It is used after global configuration and specifies that the port will use 802.1X authentication. Without the global command, this interface command alone will not enable 802.1X. Thus, it is not the correct answer for global enablement.
- ✗
dot1x pae authenticator
Why it's wrong here
The command 'dot1x pae authenticator' is configured on an interface to set the Port Access Entity (PAE) role as the authenticator. It is an interface-level command, not a global command. While it is part of 802.1X configuration, it does not enable 802.1X globally. The global command 'dot1x system-auth-control' is required first. Therefore, this option is not correct for enabling 802.1X globally.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.