mediumMultiple Choice
350-401 Practice Question: Examine the following configuration on a Cisco…
Examine the following configuration on a Cisco IOS-XE switch:
interface GigabitEthernet1/0/6 switchport mode access
authentication port-control auto dot1x pae authenticator dot1x timeout tx-period 3 dot1x max-req 3 dot1x timeout supp-timeout 10
What is the total time the switch will wait for a supplicant to respond before failing authentication?
⚠ Common exam trap
Cisco often tests the distinction between `tx-period` (retransmission interval) and `supp-timeout` (response wait time), leading candidates to mistakenly add or multiply the wrong timers to calculate the total authentication timeout.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
9 seconds
The switch waits for a supplicant to respond to each 802.1X EAP-Request/Identity frame. With `dot1x max-req 3`, the switch sends up to 3 retransmissions. The `dot1x timeout tx-period 3` sets the interval between retransmissions to 3 seconds. Therefore, the total time before authentication fails is 3 retransmissions × 3 seconds = 9 seconds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
30 seconds
Why it's wrong here
This incorrectly multiplies the tx-period by the EAP supplicant timeout (supp-timeout). Even though supp-timeout is 10 seconds, that timer governs how long the authenticator waits for a response to an EAP request after the identity exchange is complete, not the initial EAP-Request/Identity retransmission interval. A total of 30 seconds would occur only if the identity request were sent three times with a 10-second interval, which does not match the configured tx-period of 3 seconds.
- ✓
9 seconds
Why this is correct
The authenticator retransmits the EAP-Request/Identity frame with a tx-period of 3 seconds between retransmissions. With a maximum of three identity request attempts, the switch sends frames at 0s, 3s, and 6s, and then waits one final tx-period before declaring the client unresponsive. This yields a cumulative 9 seconds (3 × 3s) before the switch gives up on the unauthenticated host.
- ✗
10 seconds
Why it's wrong here
This equals the supp-timeout value, which is 10 seconds. However, the supp-timeout is applied after the switch has received a valid EAP identity response, when the authenticator is waiting for the supplicant's next EAP packet (e.g., EAP-Response after an EAP-Request). It does not affect the retransmission of the initial EAP-Request/Identity, so the 10-second timer is irrelevant to the time to give up on the initial identity request.
- ✗
13 seconds
Why it's wrong here
This appears to be an ad-hoc sum of the tx-period (3 seconds) and the supp-timeout (10 seconds). That addition is not a valid way to compute the total timeout because the two timers are sequential, not parallel: the supp-timeout is not triggered until after the identity is received. The switch runs the identity retransmission cycle solely with the 3-second tx-period for the three attempts, so combining the timers produces a meaningless duration.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the default quiet-period timer value in Cisco IOS 802.1X configuration?
easy- A.30 seconds
- ✓ B.60 seconds
- C.120 seconds
- D.10 seconds
Why B: The default quiet-period timer in Cisco IOS 802.1X configuration is 60 seconds. This timer defines the period the switch waits after a failed authentication attempt before re-initiating authentication with the same supplicant. It prevents repeated authentication attempts from overwhelming the switch and the RADIUS server.
Variation 2. What is the default tx-period timer value in Cisco IOS 802.1X configuration?
easy- A.3 seconds
- B.10 seconds
- ✓ C.30 seconds
- D.60 seconds
Why C: The default tx-period timer in Cisco IOS 802.1X configuration is 30 seconds. This timer controls how often the authenticator (switch) retransmits EAP-Request/Identity frames to the supplicant if no response is received. The 30-second default is defined in the IEEE 802.1X standard and is used to balance network responsiveness with avoiding excessive authentication traffic.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.