mediumMultiple Choice
350-401 Practice Question: Is configuring 802.1X on a Cisco switch for a…
A network engineer is configuring 802.1X on a Cisco switch for a voice VLAN deployment. The switchport is connected to an IP phone, which then connects to a PC. The engineer configures the interface with 'authentication port-control auto', 'dot1x pae authenticator', and 'switchport voice vlan 10'. The PC authenticates successfully, but the IP phone does not get an IP address from the voice VLAN. The engineer verifies that the phone is configured for 802.1X and the RADIUS server is correct. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that configuring 'authentication port-control auto' and 'dot1x pae authenticator' alone is sufficient for all devices, when in fact non-802.1X-capable devices like IP phones require MAB as a fallback mechanism to be placed into the voice VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP phone does not support 802.1X and is not configured for MAB.
The IP phone fails to obtain an IP address from the voice VLAN because it is configured for 802.1X but does not support it, and the switchport is not configured for MAC Authentication Bypass (MAB). Without MAB, the switch will not place the phone into the voice VLAN until it successfully authenticates. Since the phone cannot complete 802.1X, it remains in the data VLAN or an unauthorized state, preventing it from receiving a voice VLAN IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IP phone does not support 802.1X and is not configured for MAB.
Why this is correct
In a port running 802.1X, the switch treats the phone as an endpoint that must authenticate before the voice VLAN is applied. Because the phone cannot run the 802.1X supplicant and MAB is not enabled, the switch never receives a successful authentication to classify the device as voice, so the port remains in the unauthorized state and the locally configured `switchport voice vlan` is not assigned. The phone therefore stays on the data VLAN or gets no usable VLAN.
- ✗
The switchport is missing 'switchport mode access' command.
Why it's wrong here
The `switchport voice vlan` command is valid on both access and trunk interfaces in Cisco IOS, so omitting `switchport mode access` does not prevent the voice VLAN from being configured or active. On an access port, the voice VLAN is carried as an 802.1Q tag; on a trunk, the voice VLAN can be carried as a regular VLAN. The problem here is authentication, not the interface mode.
- ✗
The RADIUS server is not sending the voice VLAN ID in the Access-Accept.
Why it's wrong here
The voice VLAN can be configured locally with `switchport voice vlan <vlan-id>` and does not depend on RADIUS returning a VLAN attribute. RADIUS can override the voice VLAN using Cisco AVPairs, but if the local configuration is present, the phone is placed in that VLAN after successful authentication or CDP detection. Thus, the missing RADIUS voice-VLAN attribute would not cause the phone to fail to get a voice VLAN.
- ✗
The PC is using the voice VLAN instead of the data VLAN.
Why it's wrong here
The PC and phone authenticate in separate domains on the same physical port, and the PC is normally assigned to the data VLAN, not the voice VLAN. A PC cannot claim the voice VLAN unless RADIUS explicitly tags it with a voice device classification, and if that happened the symptom would be data traffic on the voice VLAN, not the phone's total lack of voice VLAN. The actual failure is upstream: the phone never authenticates.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.