Courseiva
Question 66 of 464
Network SecuritymediumMultiple ChoiceObjective-mapped

802.1X RADIUS Server Requirement

A company is implementing 802.1X port-based authentication on its wired network to ensure only authorized devices can connect. Which of the following servers is required to authenticate users and devices?

Quick Answer

RADIUS is the answer because 802.1X itself isn't an authentication protocol - it's a framework for carrying authentication traffic between three parties: the supplicant (the connecting device), the authenticator (the switch or access point), and the authentication server that actually makes the accept/reject decision. The switch never validates credentials on its own; it only forwards EAP-encapsulated requests it receives over EAPoL to a backend server, then obeys whatever decision comes back by opening or leaving the port closed. RADIUS is the protocol built for that backend role, able to carry different EAP methods (such as PEAP or EAP-TLS) and return a clear Accept or Reject that the switch can act on immediately. Other server types you might see as distractors - like a plain directory service or a DNS/DHCP server - don't participate in this exchange at all, since they aren't designed to speak the RADIUS protocol or process EAP requests. Once you recognize a question describing devices being checked against credentials before a switch port opens, look for the piece of the puzzle that terminates the authentication conversation and hands back a decision - that's the authentication server, and on the exam that role is almost always filled by RADIUS.

⚠ Common exam trap

The N10-009 exam often tests the misconception that TACACS+ can replace RADIUS in 802.1X environments, but TACACS+ encrypts the entire packet body and is designed for device administration (e.g., CLI access), not for 802.1X port-based authentication, which mandates RADIUS per the IEEE 802.1X standard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A) RADIUS server

802.1X port-based authentication relies on the Extensible Authentication Protocol (EAP) over LAN (EAPoL) between the supplicant (device) and the authenticator (switch), which then forwards authentication requests to a central authentication server. A RADIUS server is the required backend because it validates credentials (e.g., username/password or certificates) and returns an Accept/Reject decision to the switch, enabling or disabling the port. RADIUS is the standard protocol defined in IEEE 802.1X for this purpose, supporting EAP methods like PEAP, EAP-TLS, and EAP-FAST.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A) RADIUS server

    Why this is correct

    Correct. RADIUS is the most common protocol for 802.1X authentication and is widely supported.

  • B) Syslog server

    Why it's wrong here

    Syslog servers collect log messages but do not perform authentication.

  • C) TACACS+ server

    Why it's wrong here

    TACACS+ can be used for authentication, but RADIUS is the standard for 802.1X. Additionally, TACACS+ is proprietary to Cisco.

    When this WOULD be correct

    A question asks: 'Which server is used to authenticate network administrators when they log into routers and switches?' In that context, TACACS+ would be the correct answer because it separates authentication, authorization, and accounting for device administration.

  • D) NTP server

    Why it's wrong here

    NTP provides time synchronization, not authentication.

    When this WOULD be correct

    A question asking which server ensures accurate timestamps for logs or certificate validation in a PKI environment would have NTP as the correct answer. For example: 'A company needs to synchronize clocks for log correlation and certificate validity checks. Which server is required?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

A) RADIUS serverCorrect answer

Why this is correct

Correct. RADIUS is the most common protocol for 802.1X authentication and is widely supported.

C) TACACS+ serverWrong answer — click to see why

Why this is wrong here

TACACS+ is used for device administration authentication (e.g., router/switch login), not for 802.1X port-based network access control. 802.1X requires a RADIUS server to authenticate users and devices connecting to the network.

★ When this WOULD be the correct answer

A question asks: 'Which server is used to authenticate network administrators when they log into routers and switches?' In that context, TACACS+ would be the correct answer because it separates authentication, authorization, and accounting for device administration.

Why candidates choose this

Candidates confuse TACACS+ with RADIUS because both are AAA protocols. They may think TACACS+ can also handle network access authentication, but 802.1X specifically requires RADIUS.

D) NTP serverWrong answer — click to see why

Why this is wrong here

NTP (Network Time Protocol) servers synchronize clocks across network devices, but they do not perform authentication of users or devices. 802.1X requires a RADIUS server to validate credentials and authorize access.

★ When this WOULD be the correct answer

A question asking which server ensures accurate timestamps for logs or certificate validation in a PKI environment would have NTP as the correct answer. For example: 'A company needs to synchronize clocks for log correlation and certificate validity checks. Which server is required?'

Why candidates choose this

Candidates may confuse NTP with authentication servers because time synchronization is critical for Kerberos and certificate-based authentication, leading them to incorrectly assume NTP is part of the 802.1X authentication process.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on N10-009

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is implementing 802.1X port-based authentication on its wired network to control access. The network uses Active Directory for user accounts. Which type of server must be deployed to authenticate clients connecting to the switch ports?

hard
  • A.A DNS server
  • B.A DHCP server
  • C.A RADIUS server
  • D.A Kerberos server

Why C: 802.1X port-based authentication requires a RADIUS server to act as the authentication server that validates client credentials against the identity store (Active Directory). The switch (authenticator) forwards EAP frames from the client (supplicant) to the RADIUS server, which checks the credentials and instructs the switch to grant or deny port access.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.