Courseiva
Question 420 of 464
Network SecuritymediumMultiple ChoiceObjective-mapped

802.1X Standard for Network Access Control

A company is implementing network access control to ensure only authenticated users can connect to the wired network. Users must authenticate using their domain credentials before gaining full network access. Which standard should be implemented?

Quick Answer

The answer is 802.1X, the IEEE standard for port-based network access control (PNAC). This standard is correct because it uses the Extensible Authentication Protocol (EAP) to authenticate users at the switch port level, requiring valid domain credentials before granting full network access to a wired or wireless LAN. On the CompTIA Network+ N10-009 exam, this question tests your understanding of how 802.1X enforces authentication at Layer 2, often appearing in scenarios involving corporate networks that integrate with RADIUS servers and Active Directory. A common trap is confusing 802.1X with MAC filtering or captive portals—remember that 802.1X authenticates the user, not the device’s MAC address. Memory tip: think “1X = one user, one port, one authentication.”

⚠ Common exam trap

The N10-009 exam often tests 802.1X by contrasting it with 802.11i, trapping candidates who confuse wireless security standards with wired port-based access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

802.1X

802.1X is the IEEE standard for port-based network access control (PNAC). It uses the Extensible Authentication Protocol (EAP) to authenticate devices attempting to connect to a wired or wireless LAN, requiring valid domain credentials before the switch port grants full network access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 802.1X

    Why this is correct

    802.1X provides authentication for devices attempting to connect to a network port, verifying credentials against a central server.

  • 802.3af

    Why it's wrong here

    802.3af is the Power over Ethernet (PoE) standard, not related to authentication.

    When this WOULD be correct

    A question asking which standard enables a switch to provide power to IP cameras or wireless access points over the same Ethernet cable would have 802.3af as the correct answer.

  • 802.11i

    Why it's wrong here

    802.11i is a wireless security standard (WPA2), not applicable to wired network authentication.

    When this WOULD be correct

    A company wants to secure its wireless network by implementing strong encryption and authentication for Wi-Fi connections, requiring users to authenticate with domain credentials before accessing the wireless LAN.

  • 802.1Q

    Why it's wrong here

    802.1Q is the VLAN tagging standard, used for trunking, not authentication.

    When this WOULD be correct

    A question asking which standard is used to tag Ethernet frames with VLAN membership information, such as 'A company needs to separate traffic on a single physical switch into multiple logical networks. Which standard should be implemented?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

802.1XCorrect answer

Why this is correct

802.1X provides authentication for devices attempting to connect to a network port, verifying credentials against a central server.

802.3afWrong answer — click to see why

Why this is wrong here

802.3af is a Power over Ethernet (PoE) standard that defines how power is delivered over Ethernet cabling, not a network access control mechanism for authenticating users.

★ When this WOULD be the correct answer

A question asking which standard enables a switch to provide power to IP cameras or wireless access points over the same Ethernet cable would have 802.3af as the correct answer.

Why candidates choose this

Candidates may confuse the '802.3' prefix with authentication standards or mistakenly think PoE involves some form of device authorization.

802.11iWrong answer — click to see why

Why this is wrong here

802.11i is a wireless security standard (WPA2) that provides encryption and authentication for Wi-Fi networks, not for wired network access control.

★ When this WOULD be the correct answer

A company wants to secure its wireless network by implementing strong encryption and authentication for Wi-Fi connections, requiring users to authenticate with domain credentials before accessing the wireless LAN.

Why candidates choose this

Candidates may confuse 802.11i with 802.1X because both involve authentication, but 802.11i is specific to wireless, while the question explicitly mentions a wired network.

802.1QWrong answer — click to see why

Why this is wrong here

802.1Q is a standard for VLAN tagging, not for network access control or authentication. It does not provide any mechanism to authenticate users before granting network access.

★ When this WOULD be the correct answer

A question asking which standard is used to tag Ethernet frames with VLAN membership information, such as 'A company needs to separate traffic on a single physical switch into multiple logical networks. Which standard should be implemented?'

Why candidates choose this

Candidates may confuse 802.1Q with 802.1X due to similar numbering, or mistakenly think VLAN tagging involves authentication because it controls network segmentation.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on N10-009

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to enforce network access control such that only authenticated users can connect to the wired network. The authentication server will use RADIUS. Which IEEE standard should be implemented?

medium
  • A.802.11i
  • B.802.1X
  • C.802.3af
  • D.802.1Q

Why B: 802.1X is the IEEE standard for port-based network access control (PNAC). It provides a framework for authenticating devices before granting access to a wired or wireless LAN, using an authentication server such as RADIUS. This directly meets the requirement to enforce network access control so that only authenticated users can connect to the wired network.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.