Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureEasy

A network administrator is configuring a new Cisco Catalyst 9300 switch. The requirement is to ensure that when a new device connects to a port, it first authenticates with a RADIUS server before gaining network access. If authentication fails, the device should be placed in a restricted VLAN. Which feature should the administrator configure?

  1. A802.1X authentication
  2. BVLAN Trunking Protocol (VTP)
  3. CSpanning Tree Protocol (STP)
  4. DLink Layer Discovery Protocol (LLDP)
Show answer & explanation

Correct answer: A. 802.1X authentication

802.1X authentication provides port-based network access control, requiring devices to authenticate before gaining full network access. If authentication fails, policies can be applied, such as placing the device in a restricted VLAN.

Why the other options are wrong

  • B. VTP is used for managing VLANs across a switched network, not for device authentication.
  • C. STP prevents network loops and does not provide device authentication.
  • D. LLDP is a vendor-neutral protocol used for device discovery, not for authentication.

802.1X Authentication

A port-based network access control protocol that restricts unauthorized devices from connecting to a LAN.

  • Requires client authentication (e.g., username/password, certificate).
  • Uses a RADIUS server for authentication.
  • Controls network access at the switch port level.

Memory trick: Only authorized guests get through the 802.1X door.

More Infrastructure questions