Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring a Cisco switch for 802.1X with…

A network engineer is configuring a Cisco switch for 802.1X with RADIUS authentication. The switch is also configured with 'aaa authentication dot1x default group radius'. The engineer wants to use a single RADIUS server for both authentication and accounting. The RADIUS server is configured with the same shared secret for both services. The engineer configures 'radius-server host 10.1.1.1 auth-port 1812 acct-port 1813 key cisco123'. However, accounting records are not being sent to the server. The engineer verifies that the RADIUS server is reachable and that accounting is enabled on the server. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between authentication and accounting configuration, leading candidates to assume that enabling authentication automatically enables accounting, when in fact they require separate commands under the 'aaa' configuration mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch is missing the 'aaa accounting dot1x default start-stop group radius' command to enable accounting for 802.1X sessions.

The switch is configured for RADIUS authentication but lacks the 'aaa accounting dot1x default start-stop group radius' command, which is required to enable accounting for 802.1X sessions. Without this command, the switch will not send accounting records to the RADIUS server, even if the server is reachable and accounting is enabled on it. The 'aaa authentication dot1x default group radius' command only enables authentication, not accounting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The switch is missing the 'aaa accounting dot1x default start-stop group radius' command to enable accounting for 802.1X sessions.

    Why this is correct

    In Cisco IOS, 802.1X authentication can succeed while accounting remains inactive because accounting is an independent AAA service. The `aaa accounting dot1x default start-stop group radius` command explicitly instructs the switch to generate start and stop records for authenticated sessions and forward them to the RADIUS server. Simply defining a RADIUS server or enabling authentication does not create accounting traffic, so without this global configuration command, the switch will never send interim or final accounting updates.

  • ✗

    The RADIUS server is using a different accounting port than 1813; the switch should use port 1646.

    Why it's wrong here

    Incorrect because RADIUS accounting officially uses UDP port 1813; port 1646 is legacy but still used by some servers. However, the scenario states the server is configured with the same secret for both, and the port is likely correct; the issue is missing accounting configuration.

  • ✗

    The switch must have 'aaa new-model' configured before accounting can work.

    Why it's wrong here

    While `aaa new-model` is a global prerequisite that enables all AAA commands, the scenario already has authentication working, which proves `aaa new-model` is active. The command is not the missing element; it is a one-time toggle that does not selectively control accounting. Since authentication is functioning, the absence of accounting is due to the lack of a separate accounting configuration, not the absence of `aaa new-model`.

  • ✗

    The RADIUS server's shared secret for accounting is different from the authentication secret.

    Why it's wrong here

    The RADIUS protocol uses the same shared secret for both authentication and accounting packets; they are different UDP ports (1812 and 1813) but the key is shared. The scenario explicitly states that the server is configured with the same secret for both, and the switch also uses a single key configured under `radius server`. A mismatch in shared secrets would typically cause authentication to fail as well, but since authentication is working, a secret misconfiguration is not the root cause of missing accounting.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.