Courseiva
Question 860 of 1,420
hardMultiple ChoiceObjective-mapped

350-401 Practice Question: Is deploying 802.1X with Cisco ISE for a wired…

A network engineer is deploying 802.1X with Cisco ISE for a wired network. The engineer wants to use CoA (Change of Authorization) to dynamically change the VLAN of a user after authentication. The engineer configures the switch with 'aaa server radius dynamic-author' and the ISE with CoA settings. When the engineer tests CoA from ISE, the switch logs show 'CoA request received' but the VLAN does not change. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The switch is missing the 'authentication command bounce-port' or 'authentication command disable-port' configuration.

CoA requires the switch to accept and process the request. The switch must have the 'authentication command bounce-port' or 'authentication command disable-port' configured to apply changes. Option B is correct because without this, the switch may acknowledge but not act. Option A is incorrect because the switch received the request. Option C is incorrect because the RADIUS server is reachable. Option D is incorrect because the switchport mode does not prevent CoA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The ISE is not configured with the correct shared secret for CoA.

    Why it's wrong here

    Incorrect because the switch received the request, indicating shared secret is correct.

  • The switch is missing the 'authentication command bounce-port' or 'authentication command disable-port' configuration.

    Why this is correct

    Correct because these commands enable the switch to apply CoA actions like VLAN change.

  • The switch is not configured with 'dot1x pae authenticator' on the interface.

    Why it's wrong here

    Incorrect because 802.1X is already working; CoA is a separate feature.

  • The switchport is configured as 'switchport mode trunk', which does not support VLAN changes via CoA.

    Why it's wrong here

    Incorrect because CoA can change VLAN on trunk ports as well.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 18, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.