Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A company is implementing a new wireless network and requires strong authentication for all users connecting to the Wi-Fi. The solution must integrate with the existing corporate Active Directory for user credentials and provide dynamic VLAN assignment based on user groups. Which IEEE 802.1X component is responsible for authenticating the client device against the authentication server?

  1. AEAP Method
  2. BAuthentication Server
  3. CAuthenticator
  4. DSupplicant
Show answer & explanation

Correct answer: C. Authenticator

The Authenticator (typically the wireless access point or switch) receives authentication requests from the Supplicant and relays them to the Authentication Server. It acts as an intermediary, enforcing access control based on the server's response.

Why the other options are wrong

  • A. The EAP Method is the protocol used for the actual authentication exchange, not a component.
  • B. The Authentication Server (e.g., Cisco ISE, RADIUS) verifies user credentials.
  • D. The Supplicant is the client device requesting access.

802.1X Authenticator

A network device (e.g., switch or wireless access point) that acts as an intermediary between the supplicant and the authentication server in an 802.1X deployment.

  • Forwards authentication requests (EAP messages) from the supplicant to the authentication server.
  • Relays authentication responses from the server back to the supplicant.
  • Enforces access control by blocking or allowing network traffic based on the authentication result.
  • Typically a switch port or wireless access point.

Memory trick: SAC: Supplicant Asks, Authenticator Connects, Server Checks

More Security questions