350-401 Security Practice Question
A network engineer is deploying 802.1X on Catalyst access switches with Cisco ISE as the RADIUS server. Some endpoints, such as printers and badge readers, do not support 802.1X supplicants. The design must allow these devices onto a restricted VLAN while still requiring authentication for laptops. Which TWO mechanisms should the engineer configure to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is disabling 802.1X on ports used by non-supplicant devices, which removes authentication instead of adding a fallback method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure MAB (MAC Authentication Bypass) on the switch ports to authenticate non-supplicant devices using their MAC address against ISE.
The design needs one port configuration that serves both endpoint types. MAB authenticates non-supplicant devices by MAC address through ISE, and the authentication order of dot1x followed by mab ensures supplicant-capable laptops use 802.1X while printers and badge readers fall back to MAB. Together these provide differentiated, authenticated access without per-port manual reconfiguration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure MAB (MAC Authentication Bypass) on the switch ports to authenticate non-supplicant devices using their MAC address against ISE.
Why this is correct
MAB allows devices without an 802.1X supplicant to be authenticated by their MAC address, which ISE validates against its identity store or profiling database. This lets printers and badge readers obtain limited access through the same port configuration that serves supplicant-capable laptops. MAB is the standard fallback for non-supplicant endpoints in Cisco 802.1X deployments.
- ✗
Apply an ACL that permits only MAC addresses in the OUI range of the printer vendor.
Why it's wrong here
OUI-based ACLs are brittle and can be spoofed easily, and they do not integrate with ISE authorization results. The requirement is authentication, not static filtering. This approach also fails to give laptops differentiated access based on identity, undermining the policy design.
- ✗
Configure the switch to use TACACS+ for endpoint authentication instead of RADIUS.
Why it's wrong here
TACACS+ is designed for device administration and does not support the EAP methods used by 802.1X. Endpoint authentication requires RADIUS, and ISE exposes RADIUS services for exactly this purpose. Switching protocols would break the supplicant-based authentication flow entirely.
- ✗
Disable 802.1X on the ports used by non-supplicant devices and assign them to a static VLAN.
Why it's wrong here
Disabling 802.1X on those ports removes authentication entirely, so any device plugged into them would gain the static VLAN access. That violates the requirement to still require authentication for laptops. The correct approach keeps 802.1X enabled and adds a fallback method for non-supplicant endpoints.
- ✓
Enable authentication order dot1x mab on the switch ports so the switch tries 802.1X first and falls back to MAB.
Why this is correct
The authentication order command defines which method the switch attempts first. Setting dot1x then mab means supplicant-capable laptops authenticate via 802.1X, while non-supplicant devices time out on EAPOL and fall back to MAB. This single port configuration satisfies both endpoint classes without separate port profiles.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.