mediumMultiple Choice
350-401 Practice Question: Examine the following configuration snippet:…
Examine the following configuration snippet:
interface GigabitEthernet1/0/2 switchport mode access
authentication port-control auto mab dot1x pae authenticator dot1x timeout tx-period 10
Which statement about this configuration is true?
⚠ Common exam trap
Cisco often tests the order of authentication methods (802.1X first, then MAB) and the misconception that MAB is attempted before 802.1X, which is incorrect because 802.1X is always the primary method unless explicitly overridden with 'authentication order' or 'authentication priority' commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X will be attempted first; if the client does not respond, MAB will be used as a fallback.
The configuration sets the switchport as an 802.1X authenticator (dot1x pae authenticator) with MAB enabled. By default, 802.1X is attempted first; if the client does not respond to EAPOL requests (e.g., due to lack of 802.1X supplicant), the switch falls back to MAB, which uses the source MAC address for authentication. The dot1x timeout tx-period 10 sets the interval for retransmitting EAPOL-Start frames, reinforcing the initial 802.1X attempt before fallback.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAB will be attempted first, and if it fails, 802.1X will be used.
Why it's wrong here
This option reverses the default order. On a port with both 802.1X and MAB enabled, the authenticator state machine always begins with EAPOL-Request/Identity frames to detect an 802.1X-capable supplicant. Only after the EAPOL timeout expires with no response does the switch trigger MAB, which then sends a RADIUS Access-Request using the source MAC address as the identity. MAB is explicitly a fallback for non-802.1X devices, never the first method.
- ✓
802.1X will be attempted first; if the client does not respond, MAB will be used as a fallback.
Why this is correct
This is correct. The switch, acting as the authenticator, first sends EAPOL-Request/Identity frames and waits for the client's EAPOL response. If the client is not 802.1X-capable or has no supplicant enabled, it will not respond; after the EAPOL timeout expires, the switch falls back to MAB. MAB then performs a RADIUS authentication using the MAC address as both username and password, allowing legacy devices such as printers or IP phones to authenticate without a supplicant.
- ✗
The port will be placed in a guest VLAN if both 802.1X and MAB fail.
Why it's wrong here
A guest VLAN is not automatically applied when both 802.1X and MAB fail. It must be explicitly configured on the interface using commands such as dot1x guest-vlan or authentication event fail action authorize vlan. In the absence of such a configuration, a port that fails both methods remains in the unauthorized state (or continues with the default security behavior), rather than being placed into any particular VLAN. Therefore this option describes a possible action only if a guest VLAN were configured, which is not the case here.
- ✗
The switch will act as a supplicant for MAB and an authenticator for 802.1X.
Why it's wrong here
The switch never acts as a supplicant for MAB or 802.1X in this scenario. In both methods the switch is the authenticator: for 802.1X it enforces EAPOL exchanges, and for MAB it sends a RADIUS Access-Request on behalf of the connecting device. The supplicant role belongs to the endpoint, such as a PC running a supplicant or any device whose MAC address is presented for MAB. Confusing these roles is incorrect and would misunderstand the control-plane direction: the switch authenticates the client, not the other way around.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.