300-715 · Question #341
Which device acts as an authenticator during the 802.1X authentication process?
The correct answer is B. Cisco switch. In an 802.1X authentication process, the Cisco switch acts as the authenticator, mediating communication between the supplicant (endpoint) and the authentication server (Cisco ISE/RADIUS). The authenticator's role is to enforce authentication before granting network access.
Question
Which device acts as an authenticator during the 802.1X authentication process?
Options
- ARADIUS server
- BCisco switch
- CLDAP server
- DCisco ISE PSN
How the community answered
(23 responses)- A4% (1)
- B87% (20)
- C9% (2)
Why each option
In an 802.1X authentication process, the Cisco switch acts as the authenticator, mediating communication between the supplicant (endpoint) and the authentication server (Cisco ISE/RADIUS). The authenticator's role is to enforce authentication before granting network access.
The RADIUS server acts as the authentication server, verifying credentials and sending access-accept/reject messages, not as the authenticator.
In the 802.1X framework, the authenticator is the network access device (NAD) that controls physical access to the network and relays authentication messages between the supplicant and the authentication server. A Cisco switch, when configured for 802.1X, performs this role by blocking unauthorized traffic and forwarding EAP messages to the RADIUS server.
An LDAP server is an identity store queried by a RADIUS server, but it does not directly participate as an authenticator in the 802.1X handshake.
A Cisco ISE PSN (Policy Service Node) hosts the RADIUS server functionality, acting as the authentication server, not the authenticator.
Concept tested: 802.1X authentication roles
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html#concept_75628DD1B62B447A83416F928A67B4DF
Topics
Community Discussion
No community discussion yet for this question.