Courseiva
Access Controls →mediumMultiple Select

SSCP Access Controls Practice Question

A security administrator is configuring a network access control deployment that must authenticate employee laptops before they receive an IP address on the corporate VLAN. The administrator wants to use the IEEE 802.1X framework. Which two components are required for this framework to function? (Choose two.)

⚠ Common exam trap

The trap here is treating optional supporting infrastructure, such as revocation lists or captive portals, as core framework roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An authenticator that controls the port until authentication succeeds

The framework defines three roles, and the question asks for the two that the administrator must supply beyond the endpoint itself: the authenticator, which enforces port state on the switch or access point, and the authentication server, which validates credentials and returns authorization attributes. Together they hold the laptop in a pre-authentication state until the decision is rendered, which is what prevents an unauthenticated device from obtaining a corporate address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A certificate revocation list published by the endpoint vendor

    Why it's wrong here

    A revocation list may support certificate validation when the chosen method uses certificates, but it is not a required component of the 802.1X framework itself. Deployments using password-based methods such as protected extensible authentication protocol with a tunneled method do not consult a vendor revocation list at all. Presenting it as mandatory misstates the framework's architecture.

  • ✗

    A domain name system server that resolves the switch management address

    Why it's wrong here

    Name resolution for management access is an operational convenience unrelated to port-based authentication. The framework's decision flow depends on the supplicant, the authenticator, and the authentication server exchanging authentication messages, not on domain name resolution. Including a name server as a required component confuses general network plumbing with the specific roles the standard defines.

  • ✗

    A mandatory captive portal that collects user consent before authentication

    Why it's wrong here

    Captive portals are sometimes layered onto guest networks for user notification or registration, but they are not part of the 802.1X framework and can even interfere with supplicant negotiation. The framework defines supplicant, authenticator, and authentication server roles; consent pages are a separate web-redirection technology. Requiring a portal would add unnecessary complexity and does not satisfy any framework requirement.

  • ✓

    An authenticator that controls the port until authentication succeeds

    Why this is correct

    The authenticator is the network device, such as a switch or wireless access point, that blocks or permits traffic on the controlled port based on the outcome of authentication. Without it, there is no enforcement point to hold the laptop in an unauthenticated state before an IP address is assigned. It relays credentials between the supplicant and the authentication server, making it an essential element of the framework.

  • ✓

    An authentication server that validates the supplied credentials

    Why this is correct

    The authentication server, typically a RADIUS implementation, receives the credentials relayed by the authenticator and decides whether access is granted. It centralizes policy so the switch does not need local account data, and it returns attributes that can drive VLAN or access control list assignment. Without this decision point, the authenticator has nothing authoritative to base its port state on.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.