350-401 Security Practice Question
A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?
⚠ Common exam trap
The trap here is focusing on switch-side 802.1X host modes or RADIUS secrets while overlooking that MAB success hinges on exact MAC address formatting in the ISE endpoint database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.
MAB authentication depends on ISE matching the MAC address sent in the RADIUS request to an endpoint record. If the stored MAC format differs from the format in the Calling-Station-Id attribute, the endpoint is not matched to its identity group and authorization fails. Ensuring consistent MAC formatting resolves the rejection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.
Why this is correct
ISE matches MAB requests against endpoint MAC addresses in its database using a specific format. If the endpoint was added with a different delimiter or case than what the switch sends in the Calling-Station-Id, ISE will not match the identity group and will reject the request, causing the unauthorized state.
- ✗
The switch port is configured with authentication host-mode multi-domain instead of multi-auth.
Why it's wrong here
Multi-domain mode is designed for a single voice device and a single data device on the same port, which can still support MAB for the printer. Changing to multi-auth would allow multiple data devices but does not explain why a valid MAC in the correct ISE identity group is rejected, so this is not the likely cause.
- ✗
The RADIUS shared secret on the switch does not match the one configured for the switch in Cisco ISE.
Why it's wrong here
A RADIUS shared secret mismatch would prevent authentication requests from being processed at all, typically resulting in no response or an authentication failure for all methods, not a MAB-specific rejection. Since the switch shows MAB as the method, the request is reaching ISE, so the shared secret is likely correct.
- ✗
The switch is configured with dot1x pae authenticator on the port instead of pae supplicant.
Why it's wrong here
The authenticator role is correct for a switch port performing 802.1X and MAB; supplicant mode is for endpoints. Configuring the switch as a supplicant would be incorrect for this scenario and would not cause a MAB request to be rejected by ISE when the MAC is valid.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.