Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about 802.1X authentication…

Which two statements about 802.1X authentication with MAC Authentication Bypass (MAB) are true? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAB is used as a fallback authentication method for devices that do not support 802.1X.

Option A is correct because MAB is specifically designed as a fallback for endpoints that lack an 802.1X supplicant, such as printers, cameras, and legacy devices, allowing the switch to authenticate them by MAC address when EAPoL identity exchange fails or is absent. Option C is correct because in MAB the switch (authenticator) uses the endpoint's source MAC address as both the username and password in a RADIUS Access-Request, typically formatted as the MAC in a consistent case and delimiter scheme (e.g., aabbccddeeff or aa:bb:cc:dd:ee:ff). Option B is wrong because MAB does not use digital certificates; certificate-based authentication belongs to EAP-TLS, which requires a supplicant. Option D is wrong because MAB sends the MAC address in cleartext within RADIUS attributes (e.g., User-Name and User-Password/CHAP), not TLS-encrypted, and RADIUS itself is not inherently TLS-protected. Option E is wrong because EAPoL is used between the supplicant and the switch for 802.1X, whereas MAB is triggered precisely when no EAPoL supplicant responds, and the MAC address is carried to the RADIUS server over RADIUS, not EAPoL.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    MAB is used as a fallback authentication method for devices that do not support 802.1X.

    Why this is correct

    MAB provides fallback authentication when a device lacks an 802.1X supplicant, satisfying the stem's requirement for non-802.1X-capable endpoints. The switch learns the source MAC address and forwards it to the RADIUS server as both username and password. This permits printers, cameras and similar devices to gain network access without supplicant software.

  • ✗

    MAB requires the supplicant to present a digital certificate for authentication.

    Why it's wrong here

    MAB authenticates on the endpoint's MAC address alone, so no supplicant, certificate or cryptographic credential is presented. Certificate-based authentication belongs to EAP-TLS, which would be the choice for managed devices capable of running an 802.1X supplicant with a client certificate.

  • ✓

    In MAB, the switch sends the MAC address of the endpoint as the username and password to the RADIUS server.

    Why this is correct

    With MAB, the switch learns the endpoint's source MAC address and forwards it to the RADIUS server as both the username and password in the Access-Request, letting the server match it against a configured MAC database.

  • ✗

    MAB encrypts the MAC address using TLS before sending it to the RADIUS server.

    Why it's wrong here

    MAB sends the endpoint's MAC address to the RADIUS server inside a standard RADIUS Access-Request, not wrapped in TLS; the MAC is visible in the RADIUS packet. TLS-encrypted transport applies to EAP methods such as EAP-TLS, which MAB deliberately avoids because the device has no supplicant.

  • ✗

    MAB uses EAPoL to transport the MAC address between the switch and the endpoint.

    Why it's wrong here

    MAB is a switch-side fallback: the switch reads the source MAC from ordinary data frames and forwards it to RADIUS, so no EAPoL exchange occurs with the endpoint. EAPoL carries EAP authentication between switch and supplicant, which is precisely what a MAB device cannot perform.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.