Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A security analyst is investigating a potential breach where an unauthorized device gained access to the internal network. The network uses 802.1X authentication. Upon initial investigation, it was discovered that the attacker bypassed 802.1X by connecting their malicious device to an already authenticated IP phone, leveraging the phone's authenticated port. What 802.1X feature should have been enabled on the switch port to prevent this specific attack vector?

  1. AMAC Address Bypass (MAB)
  2. BGuest VLAN
  3. CMulti-domain authentication
  4. DPort security
Show answer & explanation

Correct answer: C. Multi-domain authentication

Multi-domain authentication (MDA) allows an IP phone and a PC connected to the phone's data port to authenticate independently on the same switch port. This ensures that even if the phone is authenticated, the connected PC still needs its own successful authentication, preventing an attacker from piggybacking on the phone's access. Port security limits MAC addresses but doesn't handle the multi-device authentication scenario as elegantly as MDA.

Why the other options are wrong

  • A. MAC Address Bypass (MAB) allows devices that don't support 802.1X to authenticate based on their MAC address, which would not prevent this attack.
  • B. A Guest VLAN provides limited access for unauthenticated devices and does not prevent an attacker from piggybacking on an authenticated device.
  • D. Port security limits the number of MAC addresses allowed on a port or binds specific MACs, but MDA is specifically designed for the scenario of multiple devices (like a phone and PC) requiring separate 802.1X authentication on one port.

802.1X Multi-domain Authentication (MDA)

An 802.1X feature that enables independent authentication for different types of devices (e.g., voice and data) connected to the same switch port, preventing unauthorized devices from leveraging an already authenticated device's access.

  • Separates voice and data authentication.
  • Enhances security for IP phone deployments.
  • Prevents piggybacking attacks.

Memory trick: Don't just authenticate the phone, authenticate everything behind it!

More Endpoint Security and Secure Network Access questions