Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring 802.1X on a Cisco switch for a…

A network engineer is configuring 802.1X on a Cisco switch for a guest network. The engineer wants to allow guests to access the internet after authentication but restrict access to internal resources. The engineer configures the switch with 'authentication port-control auto' and a downloadable ACL (dACL) from the RADIUS server. After a guest authenticates, the engineer tests connectivity and finds that the guest can access internal servers. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume the switch needs an explicit 'ip access-group' command to apply the dACL, but Cisco tests the understanding that dACLs are dynamically applied by the switch based on RADIUS attributes, not static interface configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The RADIUS server is not sending the dACL attributes in the Access-Accept message.

The most likely cause is that the RADIUS server is not sending the dACL attributes in the Access-Accept message. For a downloadable ACL to be applied, the RADIUS server must include specific attributes (e.g., Cisco-AVPair with 'ip:inacl#<seq>=permit/deny...' or using IETF attributes like Filter-ID referencing a dACL name) in the Access-Accept. Without these attributes, the switch cannot apply the dACL, and the guest retains default access, which may include internal resources if no other ACL is in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The switchport is configured as 'switchport mode trunk', which does not support dACLs.

    Why it's wrong here

    dACLs are fully supported on trunk-mode switchports; the switch applies a downloadable ACL as a per-port, per-host policy after 802.1X authentication, regardless of whether the interface is an access or trunk port. A trunk configuration does not preclude dACL enforcement, especially when a single authenticated host is mapped to the interface. Therefore, the guest's lack of restriction cannot be attributed to trunk port mode.

  • ✗

    The guest is not being authenticated; the switch is using MAB instead.

    Why it's wrong here

    If MAB were in use, the switch would still query RADIUS and would apply any dACL attributes included in the Access-Accept message, so MAB does not inherently skip dACLs. Moreover, the scenario indicates the guest completed 802.1X authentication, so MAB is not the mechanism in play. The failure to filter traffic stems from the RADIUS server not returning the dACL attributes, not from the authentication method.

  • ✗

    The switch is not configured with 'ip access-group' to apply the dACL.

    Why it's wrong here

    Downloadable ACLs are installed dynamically by the switch when the RADIUS Access-Accept includes the dACL attributes; no explicit 'ip access-group' command is required or used to bind a dACL to an 802.1X-authenticated port. Manual access-group configurations apply static ACLs and are not part of the dACL workflow, so their absence cannot explain the missing filter. The switch would automatically enforce the dACL if the RADIUS server actually delivered it.

  • ✓

    The RADIUS server is not sending the dACL attributes in the Access-Accept message.

    Why this is correct

    This is correct because the switch only applies a dACL when the RADIUS Access-Accept message contains the appropriate downloadable ACL attributes, such as Cisco-AVPair (e.g., 'ip:inacl#<acl-name>') or Filter-ID. If those attributes are absent, the switch receives no policy and therefore permits the guest's traffic without any IPv4 ACL filtering. The RADIUS server must be configured to return the dACL for the particular user or policy; otherwise, no access restrictions are enforced by the switch.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.