Courseiva
mediumMultiple Choice

350-401 Practice Question: Is implementing 802.1X for wireless users using…

An organization is implementing 802.1X for wireless users using Cisco ISE as the RADIUS server. The network engineer configures the wireless LAN controller (WLC) with 802.1X authentication. Users report that they can connect to the SSID but cannot access any network resources. The engineer checks the WLC and sees that users are authenticated and assigned to VLAN 100. The engineer also checks the switchport connecting the WLC and sees it is a trunk. What is the most likely issue?

⚠ Common exam trap

Cisco often tests the misconception that authentication success alone guarantees network access, when in fact the trunk's allowed VLAN list or the VLAN's existence on the switch can block traffic even after a successful RADIUS Access-Accept.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch trunk port does not have VLAN 100 allowed.

The users are authenticated and assigned to VLAN 100 by the RADIUS server, but the switch trunk port connecting the WLC does not have VLAN 100 in its allowed list. This means traffic from the WLC for VLAN 100 is dropped at the switch, preventing network access even though authentication succeeded. The trunk must explicitly permit VLAN 100 for the dynamic VLAN assignment to work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The RADIUS server is not sending the correct VLAN ID in the Access-Accept.

    Why it's wrong here

    This is incorrect because the symptom is that client devices receive an IP address in VLAN 100 and can associate, but cannot reach resources beyond the access switch. If the RADIUS server were sending an incorrect VLAN ID, the clients would either be placed in a different VLAN than intended (e.g., a guest VLAN) or authentication would fail outright. The problem is not on the RADIUS side; the Access-Accept is valid and correctly specifies VLAN 100 for the wireless clients.

  • ✓

    The switch trunk port does not have VLAN 100 allowed.

    Why this is correct

    This is the correct root cause. The WLC is configured to tag wireless client traffic on VLAN 100 and sends it over the uplink to the switch. The switch trunk port carrying this uplink must have VLAN 100 explicitly allowed in its allowed VLAN list; otherwise, the switch drops the tagged frames, preventing client traffic from reaching the rest of the network. Since the clients get IP addresses from a DHCP server reachable through the trunk (or at least associate successfully), the failure is at the trunk's egress filtering, not at the authentication phase.

  • ✗

    The WLC is not configured for 802.1X on the uplink to the switch.

    Why it's wrong here

    This is incorrect because 802.1X is a port-based access control method designed for point-to-point links and is not used on the uplink between a WLC and a switch. The WLC-to-switch link is normally configured as a trunk or an access port carrying multiple or a single VLAN, and it should not run 802.1X. Even if 802.1X were misconfigured on the uplink, it would not affect the drop of tagged VLAN 100 frames, because the issue is with VLAN pruning, not with port authentication.

  • ✗

    The users' devices are not configured for MAB.

    Why it's wrong here

    This is incorrect because MAB (MAC Authentication Bypass) is a fallback mechanism for devices that do not support 802.1X supplicants, such as printers or legacy devices. Wireless clients using 802.1X authenticate via the WLC, which acts as the authenticator (or passes EAP frames to the RADIUS server), and they do not require MAB. The problem described is about VLAN tagging on the trunk, not about the inability of the clients to perform 802.1X; MAB is irrelevant and would be a redundant fallback on the WLC, not a client-side setting.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.