nerdexam
Cisco

300-715 · Question #206

During a 802.1X deployment, an engineer must identify failed authentications without causing problems for the connected endpoint. Which command will successfully achieve this?

The correct answer is C. authentication open. The 'authentication open' command enables Open Authentication mode on a switch port. In this mode, the port allows all traffic to pass regardless of whether 802.1X authentication succeeds or fails. This lets administrators monitor authentication attempts, identify failures in log

Policy Enforcement

Question

During a 802.1X deployment, an engineer must identify failed authentications without causing problems for the connected endpoint. Which command will successfully achieve this?

Options

  • Adotlx system-auth-control
  • Bdotlx pae authenticator
  • Cauthentication open
  • Dauthentication port-control auto

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    87% (39)
  • D
    2% (1)

Explanation

The 'authentication open' command enables Open Authentication mode on a switch port. In this mode, the port allows all traffic to pass regardless of whether 802.1X authentication succeeds or fails. This lets administrators monitor authentication attempts, identify failures in logs, and troubleshoot policy configurations without disrupting connectivity to the endpoint. The 'dot1x system-auth-control' command globally enables 802.1X, 'dot1x pae authenticator' sets the port role, and 'authentication port-control auto' enforces authentication before granting access - all of which would block endpoints that fail authentication, causing network disruption during a deployment phase.

Topics

#802.1X#Authentication Modes#NAC Deployment#Monitoring

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice