Courseiva
Network SecuritymediumMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A network administrator wants to prevent unauthorized devices from connecting to the company's Ethernet ports. The company uses a centralized authentication server. Which IEEE standard should be implemented?

⚠ Common exam trap

Test-takers frequently confuse 802.1X with wireless security standards like 802.11i, because both involve authentication, but 802.1X is specifically for wired port-based access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

802.1X

802.1X is the IEEE standard for port-based Network Access Control (NAC) that authenticates devices before granting access to an Ethernet port. It uses a centralized authentication server (typically RADIUS) to verify credentials, preventing unauthorized devices from connecting to the network. This directly matches the requirement of controlling access at the port level with a centralized server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 802.1X

    Why this is correct

    IEEE 802.1X is a port-based network access control standard designed to prevent unauthorized devices from connecting to a wired or wireless LAN. It enforces authentication before granting network access by using the Extensible Authentication Protocol (EAP) between a supplicant (the client device), an authenticator (typically a switch or access point), and an authentication server (usually RADIUS). This process ensures that only authenticated and authorized users or devices can access network resources, effectively securing the physical access layer.

  • 802.11i

    Why it's wrong here

    IEEE 802.11i is a robust wireless security standard that specifies the security mechanisms for Wi-Fi networks, most notably defining Wi-Fi Protected Access 2 (WPA2). It provides strong encryption using AES-CCMP and robust authentication methods, including 802.1X/EAP for enterprise environments or pre-shared keys for personal use, to secure wireless communications. However, 802.11i is exclusively designed for wireless local area networks (WLANs) and is not applicable for securing or authenticating devices connected to wired Ethernet ports.

    When this WOULD be correct

    If the question asked about securing a wireless LAN against unauthorized access, 802.11i (WPA2) would be the correct answer. For example: 'A company wants to implement strong encryption and authentication for its Wi-Fi network. Which IEEE standard should be used?'

  • 802.3af

    Why it's wrong here

    IEEE 802.3af defines the Power over Ethernet (PoE) standard, which allows electrical power to be delivered to network devices over the same Ethernet cable that carries data. This standard is specifically designed to power devices such as IP phones, wireless access points, and security cameras without requiring separate power outlets. 802.3af is solely concerned with power delivery and does not incorporate any features for authenticating devices or controlling network access based on security policies.

    When this WOULD be correct

    A question asking: 'Which IEEE standard allows Ethernet switches to deliver power to devices such as IP cameras and VoIP phones?' would make 802.3af the correct answer.

  • 802.1Q

    Why it's wrong here

    IEEE 802.1Q is the standard for Virtual Local Area Network (VLAN) tagging, which enables a single physical network infrastructure to support multiple logical broadcast domains. Its primary function is to insert a tag into Ethernet frames, identifying which VLAN the frame belongs to, allowing switches to properly forward traffic across trunk links. While it provides network segmentation and traffic isolation, 802.1Q does not offer any mechanism for device authentication or access control to prevent unauthorized connections.

    When this WOULD be correct

    A network administrator needs to segment traffic on a trunk link between switches to separate different departments' traffic. Implementing 802.1Q VLAN tagging would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

802.1XCorrect answer

Why this is correct

IEEE 802.1X is a port-based network access control standard designed to prevent unauthorized devices from connecting to a wired or wireless LAN. It enforces authentication before granting network access by using the Extensible Authentication Protocol (EAP) between a supplicant (the client device), an authenticator (typically a switch or access point), and an authentication server (usually RADIUS). This process ensures that only authenticated and authorized users or devices can access network resources, effectively securing the physical access layer.

802.11iWrong answer — click to see why

Why this is wrong here

802.11i is a wireless security standard (WPA2) for Wi-Fi networks, not for controlling access to Ethernet ports. The question specifies preventing unauthorized devices from connecting to Ethernet ports, which requires a port-based network access control standard like 802.1X.

★ When this WOULD be the correct answer

If the question asked about securing a wireless LAN against unauthorized access, 802.11i (WPA2) would be the correct answer. For example: 'A company wants to implement strong encryption and authentication for its Wi-Fi network. Which IEEE standard should be used?'

Why candidates choose this

Candidates may confuse 802.11i with 802.1X because both involve authentication and security, but 802.11i is specific to wireless, while 802.1X applies to both wired and wireless networks.

802.3afWrong answer — click to see why

Why this is wrong here

802.3af is Power over Ethernet (PoE) standard, which provides power over Ethernet cables, not port-based network access control. The question asks for preventing unauthorized devices, which is addressed by 802.1X.

★ When this WOULD be the correct answer

A question asking: 'Which IEEE standard allows Ethernet switches to deliver power to devices such as IP cameras and VoIP phones?' would make 802.3af the correct answer.

Why candidates choose this

Candidates may confuse 802.3af with 802.1X due to similar numbering (802.3 vs 802.1) and the fact that both involve Ethernet ports, but they serve entirely different purposes.

802.1QWrong answer — click to see why

Why this is wrong here

802.1Q is used for VLAN tagging, not for port-based network access control. It does not authenticate devices or prevent unauthorized connections to Ethernet ports.

★ When this WOULD be the correct answer

A network administrator needs to segment traffic on a trunk link between switches to separate different departments' traffic. Implementing 802.1Q VLAN tagging would be the correct answer.

Why candidates choose this

Candidates may confuse 802.1X (port-based access control) with 802.1Q (VLAN tagging) due to similar numbering, or think that VLANs can restrict access by isolating ports, but VLANs do not authenticate devices.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.