mediumMultiple Choice
350-401 Practice Question: Is implementing 802.1X for wireless users using…
An organization is implementing 802.1X for wireless users using Cisco ISE as the RADIUS server. The network engineer configures the wireless LAN controller (WLC) with 802.1X authentication. Users report that they can connect to the SSID but cannot access any network resources. The engineer checks the WLC and sees that users are authenticated and assigned to VLAN 100. The engineer also checks the switchport connecting the WLC and sees it is a trunk. What is the most likely issue?
⚠ Common exam trap
Cisco often tests the misconception that authentication success alone guarantees network access, when in fact the trunk's allowed VLAN list or the VLAN's existence on the switch can block traffic even after a successful RADIUS Access-Accept.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch trunk port does not have VLAN 100 allowed.
The users are authenticated and assigned to VLAN 100 by the RADIUS server, but the switch trunk port connecting the WLC does not have VLAN 100 in its allowed list. This means traffic from the WLC for VLAN 100 is dropped at the switch, preventing network access even though authentication succeeded. The trunk must explicitly permit VLAN 100 for the dynamic VLAN assignment to work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The RADIUS server is not sending the correct VLAN ID in the Access-Accept.
Why it's wrong here
This is incorrect because the symptom is that client devices receive an IP address in VLAN 100 and can associate, but cannot reach resources beyond the access switch. If the RADIUS server were sending an incorrect VLAN ID, the clients would either be placed in a different VLAN than intended (e.g., a guest VLAN) or authentication would fail outright. The problem is not on the RADIUS side; the Access-Accept is valid and correctly specifies VLAN 100 for the wireless clients.
- ✓
The switch trunk port does not have VLAN 100 allowed.
Why this is correct
This is the correct root cause. The WLC is configured to tag wireless client traffic on VLAN 100 and sends it over the uplink to the switch. The switch trunk port carrying this uplink must have VLAN 100 explicitly allowed in its allowed VLAN list; otherwise, the switch drops the tagged frames, preventing client traffic from reaching the rest of the network. Since the clients get IP addresses from a DHCP server reachable through the trunk (or at least associate successfully), the failure is at the trunk's egress filtering, not at the authentication phase.
- ✗
The WLC is not configured for 802.1X on the uplink to the switch.
Why it's wrong here
This is incorrect because 802.1X is a port-based access control method designed for point-to-point links and is not used on the uplink between a WLC and a switch. The WLC-to-switch link is normally configured as a trunk or an access port carrying multiple or a single VLAN, and it should not run 802.1X. Even if 802.1X were misconfigured on the uplink, it would not affect the drop of tagged VLAN 100 frames, because the issue is with VLAN pruning, not with port authentication.
- ✗
The users' devices are not configured for MAB.
Why it's wrong here
This is incorrect because MAB (MAC Authentication Bypass) is a fallback mechanism for devices that do not support 802.1X supplicants, such as printers or legacy devices. Wireless clients using 802.1X authenticate via the WLC, which acts as the authenticator (or passes EAP frames to the RADIUS server), and they do not require MAB. The problem described is about VLAN tagging on the trunk, not about the inability of the clients to perform 802.1X; MAB is irrelevant and would be a redundant fallback on the WLC, not a client-side setting.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.