mediumMultiple Choice
350-401 Practice Question: Runs the following command on switch SW7: SW7#…
A network engineer runs the following command on switch SW7:
SW7# show authentication registrations
Authentication Method Registrations:
Method Priority Type dot1x 10 Interface mab 20 Interface webauth 30 Interface
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the misconception that the 'Priority' column indicates the method's importance or preference, when in fact a lower numeric value means it is attempted first, making the order of fallback the key takeaway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch will try 802.1X first, then MAB, then web authentication.
The command output shows authentication methods registered with their priorities. The 'Priority' column indicates the order in which the switch attempts each method: lower numbers are tried first. Since dot1x has priority 10, mab has 20, and webauth has 30, the switch will attempt 802.1X first, then MAB, then web authentication. This is the default fallback behavior for interface-based authentication on Cisco switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switch will try MAB before 802.1X.
Why it's wrong here
This is incorrect because the default authentication method priority on Cisco switches assigns 802.1X a priority value of 10, MAB a priority of 20, and web authentication a priority of 30. A lower numeric priority value indicates higher precedence, so the switch always attempts 802.1X first. MAB is only tried after 802.1X fails, typically due to a timeout or no response from a supplicant. Therefore, MAB cannot be attempted before 802.1X under the default configuration.
- ✓
The switch will try 802.1X first, then MAB, then web authentication.
Why this is correct
This is correct. On Cisco Catalyst switches, the default authentication method order is determined by the priority values: dot1x (10), mab (20), and webauth (30). The switch first attempts 802.1X to authenticate the supplicant; if that fails or times out, it falls back to MAC authentication bypass (MAB). If MAB also fails or is not applicable, the switch then falls back to web authentication as the final method. This ordering ensures the most secure method is attempted first, with less secure methods as fallbacks.
- ✗
Web authentication is the primary method.
Why it's wrong here
This is false because web authentication has the lowest default priority (30) among the three configured methods. The primary method is 802.1X, which is attempted first due to its priority of 10. Web authentication is typically used as a fallback for devices that cannot perform 802.1X and do not have their MAC address authorized via MAB. It is the last resort, not the primary method, so this statement is incorrect.
- ✗
Only 802.1X is registered.
Why it's wrong here
This statement is incorrect because, with this configuration, all three authentication methods—802.1X, MAB, and web authentication—are registered and available on the interface. The priority mechanism allows the switch to attempt each method in sequence, but all methods remain part of the authentication configuration. The ability to fall back from 802.1X to MAB and then to web authentication proves that all methods are registered. If only 802.1X were registered, the switch would not be able to fall back to MAB or web auth at all.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.