Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network security engineer is configuring 802.1X on a Cisco Catalyst switch with Cisco ISE as the RADIUS server. The switch is configured with 'dot1x system-auth-control' and the interface is set to 'authentication port-control auto'. The engineer wants to allow a printer that does not support 802.1X to connect to the network by using MAC Authentication Bypass (MAB). Which additional configuration is required on the switch interface to enable MAB?

⚠ Common exam trap

Candidates often confuse commands that define authentication order or host mode with the command that actually enables MAB functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'mab' under the interface configuration mode.

MAC Authentication Bypass (MAB) is enabled on a switch interface with the 'mab' command. This allows the switch to use the connecting device's MAC address as credentials for RADIUS authentication when 802.1X is not supported. The other commands either control host mode, set the authenticator role, or define authentication order, but none enable MAB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure 'authentication host-mode multi-auth' under the interface configuration mode.

    Why it's wrong here

    Host-mode multi-auth allows multiple devices to authenticate independently on a single port, but it does not enable MAB. It controls how many hosts can be authenticated and their authentication methods. Without 'mab', the printer would not be authenticated via MAC address. This command is related but does not fulfill the requirement to enable MAB.

  • ✓

    Configure 'mab' under the interface configuration mode.

    Why this is correct

    MAB is enabled on an interface with the 'mab' command in interface configuration mode. This allows the switch to use the device's MAC address as the username and password for RADIUS authentication when 802.1X times out. It is the standard method to support non-802.1X devices like printers. The other commands do not enable MAB.

  • ✗

    Configure 'dot1x pae authenticator' under the interface configuration mode.

    Why it's wrong here

    The 'dot1x pae authenticator' command sets the port access entity role to authenticator, which is the default on switch ports. It does not enable MAB. MAB is a separate feature that must be explicitly configured. This command is part of 802.1X configuration but does not provide MAC-based authentication for non-supplicant devices.

  • ✗

    Configure 'authentication order dot1x mab' under the interface configuration mode.

    Why it's wrong here

    The 'authentication order' command specifies the sequence in which authentication methods are attempted, but it does not enable MAB itself. MAB must be enabled with the 'mab' command. While 'authentication order dot1x mab' would define the order if MAB were enabled, it is not sufficient alone. This option is incomplete for the requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.