mediumMultiple Select
350-401 Practice Question: Which two statements about 802.1X authentication…
Which two statements about 802.1X authentication with MAC Authentication Bypass (MAB) are true? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MAB is used as a fallback authentication method for devices that do not support 802.1X.
Option A is correct because MAB is specifically designed as a fallback for endpoints that lack an 802.1X supplicant, such as printers, cameras, and legacy devices, allowing the switch to authenticate them by MAC address when EAPoL identity exchange fails or is absent. Option C is correct because in MAB the switch (authenticator) uses the endpoint's source MAC address as both the username and password in a RADIUS Access-Request, typically formatted as the MAC in a consistent case and delimiter scheme (e.g., aabbccddeeff or aa:bb:cc:dd:ee:ff). Option B is wrong because MAB does not use digital certificates; certificate-based authentication belongs to EAP-TLS, which requires a supplicant. Option D is wrong because MAB sends the MAC address in cleartext within RADIUS attributes (e.g., User-Name and User-Password/CHAP), not TLS-encrypted, and RADIUS itself is not inherently TLS-protected. Option E is wrong because EAPoL is used between the supplicant and the switch for 802.1X, whereas MAB is triggered precisely when no EAPoL supplicant responds, and the MAC address is carried to the RADIUS server over RADIUS, not EAPoL.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
MAB is used as a fallback authentication method for devices that do not support 802.1X.
Why this is correct
MAB provides fallback authentication when a device lacks an 802.1X supplicant, satisfying the stem's requirement for non-802.1X-capable endpoints. The switch learns the source MAC address and forwards it to the RADIUS server as both username and password. This permits printers, cameras and similar devices to gain network access without supplicant software.
- ✗
MAB requires the supplicant to present a digital certificate for authentication.
Why it's wrong here
MAB authenticates on the endpoint's MAC address alone, so no supplicant, certificate or cryptographic credential is presented. Certificate-based authentication belongs to EAP-TLS, which would be the choice for managed devices capable of running an 802.1X supplicant with a client certificate.
- ✓
In MAB, the switch sends the MAC address of the endpoint as the username and password to the RADIUS server.
Why this is correct
With MAB, the switch learns the endpoint's source MAC address and forwards it to the RADIUS server as both the username and password in the Access-Request, letting the server match it against a configured MAC database.
- ✗
MAB encrypts the MAC address using TLS before sending it to the RADIUS server.
Why it's wrong here
MAB sends the endpoint's MAC address to the RADIUS server inside a standard RADIUS Access-Request, not wrapped in TLS; the MAC is visible in the RADIUS packet. TLS-encrypted transport applies to EAP methods such as EAP-TLS, which MAB deliberately avoids because the device has no supplicant.
- ✗
MAB uses EAPoL to transport the MAC address between the switch and the endpoint.
Why it's wrong here
MAB is a switch-side fallback: the switch reads the source MAC from ordinary data frames and forwards it to RADIUS, so no EAPoL exchange occurs with the endpoint. EAPoL carries EAP authentication between switch and supplicant, which is precisely what a MAB device cannot perform.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
MAB Authentication
MAB Authentication is a network access control method that grants or denies device access to a network by checking the device's MAC address against a list of approved addresses.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.