SSCP Access Controls Practice Question
A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)
⚠ Common exam trap
The trap here is treating optional supporting infrastructure, such as revocation lists or captive portals, as core framework roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An authenticator that controls the port until authentication succeeds
The framework defines three roles, and the question asks for the two that the administrator must supply beyond the endpoint itself: the authenticator, which enforces port state on the switch or access point, and the authentication server, which validates credentials and returns authorization attributes. Together they hold the laptop in a pre-authentication state until the decision is rendered, which is what prevents an unauthenticated device from obtaining a corporate address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A certificate revocation list published by the endpoint vendor
Why it's wrong here
A revocation list may support certificate validation when the chosen method uses certificates, but it is not a required component of the 802.1X framework itself. Deployments using password-based methods such as protected extensible authentication protocol with a tunneled method do not consult a vendor revocation list at all. Presenting it as mandatory misstates the framework's architecture.
- ✗
A domain name system server that resolves the switch management address
Why it's wrong here
Name resolution for management access is an operational convenience unrelated to port-based authentication. The framework's decision flow depends on the supplicant, the authenticator, and the authentication server exchanging authentication messages, not on domain name resolution. Including a name server as a required component confuses general network plumbing with the specific roles the standard defines.
- ✗
A mandatory captive portal that collects user consent before authentication
Why it's wrong here
Captive portals are sometimes layered onto guest networks for user notification or registration, but they are not part of the 802.1X framework and can even interfere with supplicant negotiation. The framework defines supplicant, authenticator, and authentication server roles; consent pages are a separate web-redirection technology. Requiring a portal would add unnecessary complexity and does not satisfy any framework requirement.
- ✓
An authenticator that controls the port until authentication succeeds
Why this is correct
The authenticator is the network device, such as a switch or wireless access point, that blocks or permits traffic on the controlled port based on the outcome of authentication. Without it, there is no enforcement point to hold the laptop in an unauthenticated state before an IP address is assigned. It relays credentials between the supplicant and the authentication server, making it an essential element of the framework.
- ✓
An authentication server that validates the supplied credentials
Why this is correct
The authentication server, typically a RADIUS implementation, receives the credentials relayed by the authenticator and decides whether access is granted. It centralizes policy so the switch does not need local account data, and it returns attributes that can drive VLAN or access control list assignment. Without this decision point, the authenticator has nothing authoritative to base its port state on.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.