350-401 Security Practice Question
An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?
⚠ Common exam trap
The trap here is mixing up the fail action, which reacts to rejected credentials, with the server dead action, which reacts to an unreachable authentication server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication event server dead action authorize vlan 999
When RADIUS becomes unreachable, the switch needs an explicit policy for the resulting dead-server condition. The authentication event server dead action authorize vlan command places the port into a designated restricted VLAN, allowing limited connectivity while the outage persists. Other commands address failed credentials, host count, or pre-authentication access, none of which provide the required restricted-VLAN fallback.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
authentication open
Why it's wrong here
The authentication open command allows traffic to flow before authentication completes, effectively removing enforcement of the authentication result. While it prevents a port from blocking traffic, it grants full access rather than restricted VLAN access and does not specifically react to the server becoming unreachable. It is a monitoring or low-impact mode, not a restricted fallback policy.
- ✗
authentication host-mode multi-auth
Why it's wrong here
Host mode controls how many endpoints may authenticate on the port and how their traffic is handled. Multi-auth permits multiple devices to authenticate independently, but it says nothing about what happens when the RADIUS server is unreachable. It does not create a fallback VLAN, so it cannot satisfy the requirement for restricted access during a server outage.
- ✓
authentication event server dead action authorize vlan 999
Why this is correct
The authentication event server dead action authorize vlan command places the port into the specified restricted VLAN when the RADIUS server becomes unreachable. This allows the connected endpoint to send limited traffic instead of the port being placed in an unauthorized state, directly satisfying the requirement of continued but restricted access during a server outage.
- ✗
authentication event fail action authorize vlan 999
Why it's wrong here
The fail action handles the case where authentication is attempted and rejected, such as invalid credentials. It does not cover the scenario where the authentication server is unreachable. Using this command would address failed logins, not server outages, so it would not provide the restricted VLAN fallback during a RADIUS outage as required.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.