mediumMultiple Choice
350-401 Practice Question: Is configuring 802.1X on a Cisco switch for a…
A network engineer is configuring 802.1X on a Cisco switch for a guest network. The engineer wants to allow guests to access the internet after authentication but restrict access to internal resources. The engineer configures the switch with 'authentication port-control auto' and a downloadable ACL (dACL) from the RADIUS server. After a guest authenticates, the engineer tests connectivity and finds that the guest can access internal servers. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume the switch needs an explicit 'ip access-group' command to apply the dACL, but Cisco tests the understanding that dACLs are dynamically applied by the switch based on RADIUS attributes, not static interface configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RADIUS server is not sending the dACL attributes in the Access-Accept message.
The most likely cause is that the RADIUS server is not sending the dACL attributes in the Access-Accept message. For a downloadable ACL to be applied, the RADIUS server must include specific attributes (e.g., Cisco-AVPair with 'ip:inacl#<seq>=permit/deny...' or using IETF attributes like Filter-ID referencing a dACL name) in the Access-Accept. Without these attributes, the switch cannot apply the dACL, and the guest retains default access, which may include internal resources if no other ACL is in place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switchport is configured as 'switchport mode trunk', which does not support dACLs.
Why it's wrong here
dACLs are fully supported on trunk-mode switchports; the switch applies a downloadable ACL as a per-port, per-host policy after 802.1X authentication, regardless of whether the interface is an access or trunk port. A trunk configuration does not preclude dACL enforcement, especially when a single authenticated host is mapped to the interface. Therefore, the guest's lack of restriction cannot be attributed to trunk port mode.
- ✗
The guest is not being authenticated; the switch is using MAB instead.
Why it's wrong here
If MAB were in use, the switch would still query RADIUS and would apply any dACL attributes included in the Access-Accept message, so MAB does not inherently skip dACLs. Moreover, the scenario indicates the guest completed 802.1X authentication, so MAB is not the mechanism in play. The failure to filter traffic stems from the RADIUS server not returning the dACL attributes, not from the authentication method.
- ✗
The switch is not configured with 'ip access-group' to apply the dACL.
Why it's wrong here
Downloadable ACLs are installed dynamically by the switch when the RADIUS Access-Accept includes the dACL attributes; no explicit 'ip access-group' command is required or used to bind a dACL to an 802.1X-authenticated port. Manual access-group configurations apply static ACLs and are not part of the dACL workflow, so their absence cannot explain the missing filter. The switch would automatically enforce the dACL if the RADIUS server actually delivered it.
- ✓
The RADIUS server is not sending the dACL attributes in the Access-Accept message.
Why this is correct
This is correct because the switch only applies a dACL when the RADIUS Access-Accept message contains the appropriate downloadable ACL attributes, such as Cisco-AVPair (e.g., 'ip:inacl#<acl-name>') or Filter-ID. If those attributes are absent, the switch receives no policy and therefore permits the guest's traffic without any IPv4 ACL filtering. The RADIUS server must be configured to return the dACL for the particular user or policy; otherwise, no access restrictions are enforced by the switch.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.