Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?

⚠ Common exam trap

The trap here is mixing up the fail action, which reacts to rejected credentials, with the server dead action, which reacts to an unreachable authentication server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

authentication event server dead action authorize vlan 999

When RADIUS becomes unreachable, the switch needs an explicit policy for the resulting dead-server condition. The authentication event server dead action authorize vlan command places the port into a designated restricted VLAN, allowing limited connectivity while the outage persists. Other commands address failed credentials, host count, or pre-authentication access, none of which provide the required restricted-VLAN fallback.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    authentication open

    Why it's wrong here

    The authentication open command allows traffic to flow before authentication completes, effectively removing enforcement of the authentication result. While it prevents a port from blocking traffic, it grants full access rather than restricted VLAN access and does not specifically react to the server becoming unreachable. It is a monitoring or low-impact mode, not a restricted fallback policy.

  • ✗

    authentication host-mode multi-auth

    Why it's wrong here

    Host mode controls how many endpoints may authenticate on the port and how their traffic is handled. Multi-auth permits multiple devices to authenticate independently, but it says nothing about what happens when the RADIUS server is unreachable. It does not create a fallback VLAN, so it cannot satisfy the requirement for restricted access during a server outage.

  • ✓

    authentication event server dead action authorize vlan 999

    Why this is correct

    The authentication event server dead action authorize vlan command places the port into the specified restricted VLAN when the RADIUS server becomes unreachable. This allows the connected endpoint to send limited traffic instead of the port being placed in an unauthorized state, directly satisfying the requirement of continued but restricted access during a server outage.

  • ✗

    authentication event fail action authorize vlan 999

    Why it's wrong here

    The fail action handles the case where authentication is attempted and rejected, such as invalid credentials. It does not cover the scenario where the authentication server is unreachable. Using this command would address failed logins, not server outages, so it would not provide the restricted VLAN fallback during a RADIUS outage as required.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.