nerdexam
Cisco

200-301 · Question #696

A security administrator wants to profile endpoints and gain visibility into attempted authentications. Which 802.1x mode allows these actions?

The correct answer is A. Monitor mode. To profile endpoints and gain visibility into authentication attempts without enforcing access control, 802.1X Monitor Mode is used.

Submitted by yuki_2020· Mar 5, 2026Security Fundamentals

Question

A security administrator wants to profile endpoints and gain visibility into attempted authentications. Which 802.1x mode allows these actions?

Options

  • AMonitor mode
  • BHigh-Security mode
  • CLow-impact mode
  • DClosed mode

How the community answered

(22 responses)
  • A
    91% (20)
  • B
    5% (1)
  • D
    5% (1)

Why each option

To profile endpoints and gain visibility into authentication attempts without enforcing access control, 802.1X Monitor Mode is used.

AMonitor modeCorrect

In 802.1X Monitor Mode, the switch listens for EAP messages and forwards them to the authentication server, but it does not enforce authentication or block network access. This allows administrators to observe and log authentication attempts and endpoint characteristics for profiling purposes without disrupting network services. It is a non-disruptive way to prepare for full 802.1X deployment.

BHigh-Security mode

"High-Security mode" is not a standard 802.1X operational mode; it implies strict enforcement which is not aligned with monitoring.

CLow-impact mode

"Low-impact mode" is not a standard 802.1X operational mode; while it sounds less restrictive, it doesn't specifically describe the profiling and visibility function.

DClosed mode

Closed mode restricts all network access until successful 802.1X authentication occurs, which prevents profiling without enforcement.

Concept tested: 802.1X operational modes (Monitor Mode)

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html

Topics

#802.1x#Network Access Control#Endpoint profiling

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice