200-301 · Question #696
A security administrator wants to profile endpoints and gain visibility into attempted authentications. Which 802.1x mode allows these actions?
The correct answer is A. Monitor mode. To profile endpoints and gain visibility into authentication attempts without enforcing access control, 802.1X Monitor Mode is used.
Question
A security administrator wants to profile endpoints and gain visibility into attempted authentications. Which 802.1x mode allows these actions?
Options
- AMonitor mode
- BHigh-Security mode
- CLow-impact mode
- DClosed mode
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- D5% (1)
Why each option
To profile endpoints and gain visibility into authentication attempts without enforcing access control, 802.1X Monitor Mode is used.
In 802.1X Monitor Mode, the switch listens for EAP messages and forwards them to the authentication server, but it does not enforce authentication or block network access. This allows administrators to observe and log authentication attempts and endpoint characteristics for profiling purposes without disrupting network services. It is a non-disruptive way to prepare for full 802.1X deployment.
"High-Security mode" is not a standard 802.1X operational mode; it implies strict enforcement which is not aligned with monitoring.
"Low-impact mode" is not a standard 802.1X operational mode; while it sounds less restrictive, it doesn't specifically describe the profiling and visibility function.
Closed mode restricts all network access until successful 802.1X authentication occurs, which prevents profiling without enforcement.
Concept tested: 802.1X operational modes (Monitor Mode)
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.