SSCP Network and Communications Security Practice Question
A security team is implementing Network Access Control (NAC) to enforce endpoint compliance before granting network access. Which technology allows port-based authentication on wired networks?
⚠ Common exam trap
Many exam-takers confuse the authentication protocol (RADIUS) with the port-based access control mechanism (802.1X); candidates often select RADIUS because it is commonly used in NAC, but the question specifically asks for the technology that enables port-based authentication on wired networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X
802.1X is an IEEE standard for port-based network access control that provides authentication to devices trying to connect to a wired or wireless network. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPOL) to encapsulate authentication messages between the supplicant (client) and the authenticator (switch or access point), which then relays them to an authentication server (typically RADIUS). This ensures that no traffic can pass through the port until the device is authenticated and authorized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS
Why it's wrong here
RADIUS is the authentication server that 802.1X consults; it does not itself provide the port-based access control mechanism on the switch. It is tempting because RADIUS is central to NAC deployments, and would be the right answer if the question asked which protocol stores and validates user credentials.
- ✗
WPA2-Enterprise
Why it's wrong here
WPA2-Enterprise provides 802.1X authentication and encryption for wireless LANs, not wired switch ports. It is the right choice when securing Wi-Fi access with per-user credentials, whereas NAC on wired networks relies on 802.1X with RADIUS at the switch port.
- ✓
802.1X
Why this is correct
802.1X is the IEEE standard for port-based network access control, authenticating a supplicant via EAP before the switch port grants access. It satisfies the requirement for wired port-based authentication, unlike MAC filtering or captive portals.
- ✗
MAC filtering
Why it's wrong here
MAC filtering authenticates by hardware address, not by user credentials, so it cannot perform the port-based 802.1X authentication the scenario requires. It is tempting because it does restrict which devices may attach to a switch port, and would suit a small wired LAN where only fixed, known machines connect.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.