mediumMultiple Choice
350-401 Practice Question: Runs the following command on switch SW1: SW1#…
A network engineer runs the following command on switch SW1:
SW1# show authentication sessions interface GigabitEthernet1/0/1 Interface: GigabitEthernet1/0/1
MAC Address: 0011.2233.4455
IP Address: 192.168.1.100
Status: Authz Success Domain: DATA Oper host mode: multi-auth Oper control dir: both Session timeout: N/A Common Session ID: 0A1B2C3D4E5F6G7H8I9J Acct Session ID: 0x0000000A Handle: 0x00000001
Current Method List: mab Method: MAB State: Authz Success
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between 'multi-auth' and 'multi-domain' host modes, where candidates mistakenly assume 'multi-auth' allows only one data and one voice device, but it actually allows multiple devices of any type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The client was authenticated based on its MAC address via MAB.
The output shows the current method list as 'mab' and the method as 'MAB' with a state of 'Authz Success'. This indicates that the client was authenticated using MAC Authentication Bypass (MAB), which uses the MAC address as the credentials, not 802.1X. The 'Status: Authz Success' confirms successful authorization, and the 'Domain: DATA' indicates it is a data device, not voice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The client authenticated using 802.1X with a username and password.
Why it's wrong here
The output clearly indicates MAB (MAC Authentication Bypass) as the authentication method, not 802.1X. For 802.1X, the switch would have attempted EAP encapsulation and the client would provide a username/password (e.g., via PEAP or EAP-FAST). Since the identity shown is the MAC address and the method is MAB, the device did not actively authenticate with 802.1X credentials.
- ✓
The client was authenticated based on its MAC address via MAB.
Why this is correct
The session shows 'Method: MAB' and 'State: Authz Success', confirming that the port's MAC address was validated by the RADIUS server using MAC Authentication Bypass. This occurs when the switch does not receive an 802.1X EAP response from the client and falls back to its MAC address as the identity. The successful authorization indicates the client is accepted based on that MAC address.
- ✗
The port is in multi-domain mode, allowing one data and one voice device.
Why it's wrong here
The switch output for this port displays 'Host-Mode: MULTI-AUTH', meaning every endpoint connected to the port is authenticated individually, not just one data and one voice device. Multi-domain mode restricts the port to two devices—a data phone and a voice phone—which is not shown here. Therefore, the statement about multi-domain mode is incorrect.
- ✗
The session is for voice traffic because the domain is DATA.
Why it's wrong here
In the session output, the domain is listed as 'DATA', which explicitly identifies this as a data endpoint, not a voice device. Voice traffic would have a domain of 'VOICE' and would typically be classified via CDP or LLDP. Since this session is in the DATA domain, it cannot be carrying voice traffic.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
MAB Authentication
MAB Authentication is a network access control method that grants or denies device access to a network by checking the device's MAC address against a list of approved addresses.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.