300-715 · Question #173
Drag and Drop Question Drag the descriptions on the left onto the components of 802.1X on the right. Answer:
The correct answer is device that controls physical access to the network based on the endpoint authentication status; software on the endpoint that communicates with EAP at layer 2; device that validates the identity of the endpoint and provides results to another device. The correct approach involves dragging each 802.1X component description to its corresponding role, matching the supplicant with client software, the authenticator with the network access control device, and the authentication server with the identity validation device.
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- device that controls physical access to the network based on the endpoint authentication status
- software on the endpoint that communicates with EAP at layer 2
- device that validates the identity of the endpoint and provides results to another device
Explanation
The correct approach involves dragging each 802.1X component description to its corresponding role, matching the supplicant with client software, the authenticator with the network access control device, and the authentication server with the identity validation device.
Approach. To correctly answer this question, the test-taker must match the functional description of each 802.1X role to its correct name:
-
Drag 'software on the endpoint that communicates with EAP at layer 2' to 'supplicant'. The supplicant is the client device (or software on it) that requests access to the network and communicates using EAP (Extensible Authentication Protocol), often encapsulated in EAP over LAN (EAPOL) at Layer 2, with the authenticator.
-
Drag 'device that controls physical access to the network based on the endpoint authentication status' to 'authenticator'. The authenticator is the network device (e.g., a switch or wireless access point) that acts as a gatekeeper, controlling the supplicant's physical access to the network based on the authentication decision received from the authentication server.
-
Drag 'device that validates the identity of the endpoint and provides results to another device' to 'authentication server'. The authentication server (typically a RADIUS server) is responsible for verifying the supplicant's credentials and then communicating the authentication result (grant or deny access) back to the authenticator.
Common mistakes.
- common_mistake. A common mistake is confusing the roles of the 'authenticator' and the 'authentication server'. The authenticator is the network device that enforces access control (like a switch), while the authentication server is the backend system that actually verifies credentials (like a RADIUS server). Incorrectly associating 'device that validates the identity' with the authenticator or 'device that controls physical access' with the authentication server would be a key error. Another mistake could be misidentifying the 'supplicant' as a hardware device controlling access rather than the client software/endpoint initiating the request.
Concept tested. The core technical concept being tested is the understanding of the IEEE 802.1X standard for Port-based Network Access Control (PNAC), specifically the roles and responsibilities of its three main components: the supplicant, the authenticator, and the authentication server.
Topics
Community Discussion
No community discussion yet for this question.
