A security auditor recommends implementing a solution that authenticates users and devices before granting network access, regardless of the physical port they connect to. Which technology should be deployed?
802.1X authenticates the supplicant against a RADIUS server before the switch port grants access, tying admission to identity rather than physical location. This satisfies the auditor's requirement that users and devices be verified regardless of which port they connect to.
Why this answer
802.1X is the correct technology because it provides port-based network access control (PNAC) that authenticates users and devices before granting network access, regardless of the physical port they connect to. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPoL) to communicate with a RADIUS server, ensuring that only authenticated endpoints are allowed on the network. This meets the auditor's requirement for authentication at the port level, independent of the switch port used.
Exam trap
The trap here is that candidates often confuse port security with 802.1X because both control port access, but port security only filters by MAC address and does not provide user authentication or integration with a central authentication server, which is the key requirement in the question.
Why the other options are wrong
Port security limits MAC addresses per port but does not authenticate users or devices before granting network access; it only controls which MAC addresses are allowed on a specific switch port.
VLAN hopping is an attack technique, not a security solution. It exploits switch configuration to gain unauthorized access to VLANs, whereas the question asks for a technology that authenticates users and devices before granting network access.
DHCP snooping is a security feature that filters untrusted DHCP messages to prevent rogue DHCP servers, but it does not authenticate users or devices before granting network access.
When would these options actually be correct?
A question asks: 'Which feature prevents unauthorized devices from connecting to a switch by limiting the number of MAC addresses per port?' Then port security would be correct.
A question asking 'Which attack allows a device to access traffic from a different VLAN by manipulating trunking protocols?' would have VLAN hopping as the correct answer.
A question asks: 'Which technology prevents unauthorized DHCP servers from assigning IP addresses on a network?' In that context, DHCP snooping is the correct answer.
Why candidates pick the wrong answer
Candidates confuse port security with network access control because both deal with restricting device connections, but port security lacks authentication and is port-specific.
Candidates may confuse VLAN hopping with a security mechanism because it involves network access control at the VLAN level, but it is actually a vulnerability, not a solution.
Candidates may confuse DHCP snooping with network access control because both involve security at the switch level, leading them to think it can authenticate users.