220-1101 Networking Practice Question
A network technician is configuring a small office network. The company wants to ensure that only authorized company devices can connect to the wired network. The network uses a managed switch and a DHCP server. Which security feature should the technician configure on the switch to BEST meet this requirement?
⚠ Common exam trap
Candidates often confuse port security or MAC filtering with true authentication, but 802.1X is the only option that provides per-device authentication using an external server, which is what the question's requirement for 'authorized company devices' implies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X
802.1X is the correct answer because it provides port-based network access control (PNAC) that authenticates devices before granting access to the wired network. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPoL) to verify credentials against an authentication server (e.g., RADIUS), ensuring only authorized company devices can connect. This meets the requirement precisely by enforcing per-device authentication at the switch port level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port security
Why it's wrong here
Port security is a Layer 2 switch feature that limits the number of source MAC addresses allowed on an interface and can pin allowed addresses using sticky learning. However, this is an administrative access control based on unauthenticated MAC identifiers, and an attacker can trivially spoof a whitelisted MAC address in software. It does not verify the device's identity or require credentials, so it provides weak security compared with an authentication protocol.
- ✓
802.1X
Why this is correct
802.1X is a port-based Network Access Control standard that requires a supplicant (the client), an authenticator (the switch or access point), and an authentication server (typically RADIUS) to run EAP methods such as EAP-TLS or PEAP. Before the LAN or WLAN port is fully opened, the device must present valid credentials or a certificate, thereby authenticating the connecting device rather than merely checking its hardware address. If authentication fails, the port remains in an unauthorized state, blocking all other traffic. This gives a far stronger protection against rogue endpoints than MAC-based techniques.
- ✗
DHCP snooping
Why it's wrong here
DHCP snooping is a switch feature that monitors DHCP traffic and builds a binding table mapping client MAC addresses to IP addresses and ports, using trusted and untrusted port designations to drop messages from rogue DHCP servers. It is effective at preventing DHCP-based attacks such as DHCP starvation and IP address spoofing, but it never asks the client to prove its identity. The client authenticates itself only to the DHCP server via the DHCP protocol, which is unsecured, so DHCP snooping cannot prevent an unauthorized device from simply sending its own DHCP request and joining the network.
- ✗
MAC address filtering
Why it's wrong here
MAC address filtering involves configuring an access point or router with an allowlist (or denylist) of client MAC addresses that are permitted to associate. Since the wireless medium broadcasts frames in the air, an attacker can passively capture a valid client's MAC and then change their own interface's MAC to impersonate that device, bypassing the filter entirely. This method also imposes administrative overhead in large networks and does not provide per-session authentication, encryption binding, or key derivation.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.