hardMultiple Choice
350-401 Practice Question: An enterprise network uses 802.1X for wired access
An enterprise network uses 802.1X for wired access. The authentication server is a Cisco ISE. Recently, some Windows 10 clients fail to authenticate, while others succeed. The engineer checks the switch configuration and finds 'authentication port-control auto' and 'dot1x pae authenticator' are configured. The failing clients show 'EAP failure' in the logs. The engineer suspects a mismatch in EAP method. Which EAP method is most likely causing the issue if the ISE is configured to require EAP-TLS but the Windows clients are configured for PEAP-MSCHAPv2?
⚠ Common exam trap
Cisco often tests the concept that EAP-TLS is the only EAP method that requires a client certificate by default, and candidates may confuse it with PEAP or EAP-FAST, which do not require client certificates for the inner authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EAP-TLS requires a client certificate, which the Windows clients do not have.
EAP-TLS requires a client-side certificate for authentication. If the ISE is configured to require EAP-TLS but the Windows 10 clients are configured for PEAP-MSCHAPv2, the clients will not present a certificate, causing the ISE to send an EAP failure. This mismatch in EAP method explains why only clients without the proper certificate configuration fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EAP-TLS requires a client certificate, which the Windows clients do not have.
Why this is correct
EAP-TLS is a certificate-based mutual authentication method: the server presents a certificate and the client must also present a valid client certificate. Since the Windows clients have not been issued client certificates, the client cannot complete the TLS handshake, so authentication fails despite the server being configured for EAP-TLS. This is the root cause described in the scenario.
- ✗
EAP-FAST requires a PAC file that the Windows clients do not have.
Why it's wrong here
EAP-FAST does rely on a Protected Access Credential (PAC), but it is not implicated in this failure. The scenario explicitly contrasts EAP-TLS with PEAP-MSCHAPv2, and neither the server nor the clients are configured for EAP-FAST. Moreover, PACs can be dynamically provisioned or manually distributed, so a missing PAC is not the reason authentication fails here.
- ✗
LEAP uses a shared secret that is not configured on the clients.
Why it's wrong here
LEAP (Lightweight Extensible Authentication Protocol) uses a username/password credential pair, not a pre-shared secret, and it is a Cisco-proprietary method that predates WPA2. The scenario never mentions LEAP, and the failure involves a certificate mismatch, not a shared-secret configuration problem. Therefore, this option is incorrect because LEAP is not the protocol in use.
- ✗
EAP-MD5 does not support mutual authentication, causing the failure.
Why it's wrong here
EAP-MD5 is an older EAP method that performs only one-way authentication (the server authenticates the user) and does not support mutual authentication, which is a known weakness. However, the scenario is about a client/server certificate mismatch between EAP-TLS and PEAP, and neither the clients nor the server are configured to use EAP-MD5. Thus, while the statement about EAP-MD5 is technically true, it does not explain the failure in this scenario.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.