nerdexam
Cisco

300-430 · Question #288

An engineer must define credentials for an autonomous access point that is configured to use 802.1X authentication against the switch port is attached to. Where are the credentials defined?

The correct answer is A. RADIUS server. When an autonomous AP acts as an 802.1X supplicant authenticating to a switch port, the RADIUS server is the authentication authority that holds and validates the AP's credentials.

Security for Wireless Client Connectivity

Question

An engineer must define credentials for an autonomous access point that is configured to use 802.1X authentication against the switch port is attached to. Where are the credentials defined?

Options

  • ARADIUS server
  • BCisco Prime Infrastructure
  • Cwireless LAN controller
  • DTACACS server

How the community answered

(51 responses)
  • A
    94% (48)
  • B
    2% (1)
  • D
    4% (2)

Why each option

When an autonomous AP acts as an 802.1X supplicant authenticating to a switch port, the RADIUS server is the authentication authority that holds and validates the AP's credentials.

ARADIUS serverCorrect

In 802.1X port-based authentication, the autonomous AP is the supplicant and the switch is the authenticator; the switch forwards the AP's identity and credentials to the RADIUS server, which is the authentication server that stores the valid credentials and returns an Access-Accept or Access-Reject. The credentials (username/password or certificate) must therefore be defined on the RADIUS server so it can verify the AP's identity and permit the switchport to transition to an authorized state.

BCisco Prime Infrastructure

Cisco Prime Infrastructure is a network management platform used for monitoring and provisioning; it does not serve as an 802.1X authentication server and does not store supplicant credentials.

Cwireless LAN controller

A wireless LAN controller manages lightweight APs over CAPWAP and does not function as a RADIUS authentication server for autonomous AP 802.1X supplicant authentication to a switch.

DTACACS server

TACACS+ is a device administration protocol used for CLI access control (login, enable, command authorization), not for 802.1X port authentication, so credentials defined there would not be consulted during EAP-based port authentication.

Concept tested: 802.1X supplicant authentication for autonomous APs

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-16/sec-user-8021x-xe-16-book/config-ieee-802x-pba.html

Topics

#autonomous AP#802.1X authentication#RADIUS credentials#supplicant

Community Discussion

No community discussion yet for this question.

Full 300-430 Practice