hardMultiple Select
350-401 Practice Question: Which three statements about 802.1X port-based…
Which three statements about 802.1X port-based authentication are true? (Choose three.)
⚠ Common exam trap
350-401 often tests the role reversal between supplicant and authentication server, and the misconception that 802.1X is wireless-only, so candidates must firmly associate supplicant=client, authenticator=switch/WAP, authentication server=RADIUS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The supplicant communicates with the authenticator using EAP over LAN (EAPoL) frames.
Option A is correct because in 802.1X the supplicant (client) exchanges EAP authentication messages with the authenticator encapsulated in EAP over LAN (EAPoL) frames, as defined by IEEE 802.1X. Option B is correct because the authenticator is the network access device that controls the port—typically a LAN switch or a wireless access point—and relays EAP messages between the supplicant and the authentication server. Option D is correct because the authentication server is normally a RADIUS server that validates the supplicant's credentials and returns an Access-Accept or Access-Reject to the authenticator. Option C is incorrect because it misidentifies the supplicant; the supplicant is the client device requesting access, while the RADIUS server acts as the authentication server. Option E is incorrect because 802.1X is defined for both wired and wireless LANs and is commonly deployed on wired switches as well as WLAN infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The supplicant communicates with the authenticator using EAP over LAN (EAPoL) frames.
Why this is correct
EAPoL carries Extensible Authentication Protocol exchanges directly between the supplicant and the authenticator across the point-to-point LAN segment, satisfying 802.1X's requirement that authentication traffic terminate at the switch port before reaching the authentication server. The authenticator then relays these exchanges to RADIUS, keeping the supplicant's credentials off the wire in cleartext.
- ✓
The authenticator is typically a network switch or wireless access point.
Why this is correct
The authenticator is the device that controls physical or wireless port access and relays EAP frames between supplicant and authentication server. Switches and wireless access points fulfil this role, enforcing port state until authentication completes.
- ✗
The supplicant is the device that provides authentication services, such as a RADIUS server.
Why it's wrong here
The supplicant is the client endpoint requesting network access, while the authenticator is the switch port and the authentication server is the RADIUS service. Confusing the roles is tempting because all three participate in the exchange, but the RADIUS server is the authentication server.
- ✓
The authentication server is usually a RADIUS server that validates credentials.
Why this is correct
RADIUS carries the Extensible Authentication Protocol exchange between the authenticator and the authentication server, so the switch merely relays credentials rather than validating them itself. This satisfies the stem's requirement that 802.1X separates the authentication function from the access device, with Microsoft Entra ID or similar directories sitting behind RADIUS.
- ✗
802.1X is only supported on wireless networks and cannot be used on wired switches.
Why it's wrong here
802.1X operates at layer 2 on both wired switch ports and wireless networks, using EAPOL frames. The claim tempts because 802.1X is most visible in Wi-Fi deployments, yet wired switches commonly enforce it for port-based access control.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.