mediumMultiple Select
350-401 Practice Question: Which two statements about 802.1X port-based…
Which two statements about 802.1X port-based authentication on a Cisco switch are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the three 802.1X roles — candidates confuse the authenticator (switch) with the authentication server (RADIUS), picking the RADIUS server as the authenticator because it performs the actual credential check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch acts as the authenticator in the 802.1X framework.
Option A is correct because in the 802.1X framework the switch port functions as the authenticator, controlling access to the LAN by relaying credentials between the supplicant and the authentication server. Option D is correct because EAPoL (EAP over LAN, EtherType 0x888E) is the Layer 2 protocol used between the supplicant (client) and the authenticator (switch) to carry EAP authentication messages. Option B is wrong because the RADIUS server acts as the authentication server, not the authenticator; it validates credentials and returns Accept/Reject to the switch. Option C is wrong because 802.1X is a port-based access control method configured on switch ports (and can also run on some router interfaces), not limited to routers. Option E is wrong because 802.1X is widely deployed on wired Ethernet switch ports as well as wireless networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The switch acts as the authenticator in the 802.1X framework.
Why this is correct
In 802.1X the switch port enforces authentication, relaying EAP frames between supplicant and RADIUS server, so it is the authenticator. This satisfies the framework role the stem asks about, distinct from the supplicant (client) and authentication server.
- ✗
The RADIUS server acts as the authenticator in the 802.1X framework.
Why it's wrong here
In 802.1X the switch port is the authenticator; the RADIUS server is the authentication server that validates credentials passed by the supplicant. It is tempting because RADIUS performs the actual credential verification, but the authenticator role is the network access device controlling the port.
- ✗
802.1X can only be configured on router interfaces, not on switch ports.
Why it's wrong here
802.1X is a port-based access control standard applied to switch ports, not router interfaces, so this statement inverts the technology's actual deployment. It is tempting because 802.1X can run on routed links, but its port-based enforcement targets Layer 2 switch access ports.
- ✓
EAP over LAN (EAPoL) is used between the supplicant and the authenticator.
Why this is correct
EAPoL encapsulates EAP frames directly in Ethernet between supplicant and authenticator, so the switch terminates that Layer 2 exchange before RADIUS. This matches the stem's requirement, unlike RADIUS, which carries EAP between authenticator and authentication server.
- ✗
802.1X authentication is only applicable to wireless networks.
Why it's wrong here
802.1X operates at Layer 2 on both wired switch ports and wireless, so restricting it to wireless is factually wrong; the stem asks about switch port-based authentication, which is wired. It is tempting because 802.1X is widely associated with Wi-Fi enterprise authentication, where it is indeed commonly deployed.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.