nerdexam
Cisco

350-701 · Question #710

Which action configures the iEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

The correct answer is C. Add MAB into the switch to allow redirection to a Layer 3 device for authentication. To support Layer 3 authentication with IEEE 802.1X Flexible Authentication, a common approach is to configure MAC Authentication Bypass (MAB) on the switch, allowing devices to be redirected to a Layer 3 authentication mechanism like a web portal.

Submitted by luis.pe· Mar 30, 2026Secure Network Access, Visibility, and Enforcement

Question

Which action configures the iEEE 802.1X Flexible Authentication feature to support Layer 3 authentication mechanisms?

Options

  • AModify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external
  • BIdentify the devices using this feature and create a policy that allows them to pass Layer 2
  • CAdd MAB into the switch to allow redirection to a Layer 3 device for authentication.
  • DConfigure WebAuth so the hosts are redirected to a web page for authentication.

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    81% (17)
  • D
    5% (1)

Why each option

To support Layer 3 authentication with IEEE 802.1X Flexible Authentication, a common approach is to configure MAC Authentication Bypass (MAB) on the switch, allowing devices to be redirected to a Layer 3 authentication mechanism like a web portal.

AModify the Dot1x configuration on the VPN server to send Layer 3 authentications to an external

Modifying Dot1x configuration on a VPN server is unrelated to configuring the 802.1X Flexible Authentication feature on a switch for Layer 3 authentication of local network devices.

BIdentify the devices using this feature and create a policy that allows them to pass Layer 2

Simply identifying devices and allowing them to pass Layer 2 is a generic statement and does not specifically configure 802.1X Flexible Authentication to enable Layer 3 authentication mechanisms.

CAdd MAB into the switch to allow redirection to a Layer 3 device for authentication.Correct

Configuring MAC Authentication Bypass (MAB) on the switch allows devices that don't support 802.1X to gain initial network access based on their MAC address. Once MAB authenticates the device, the 802.1X Flexible Authentication feature can then redirect the host to a Layer 3 device (e.g., a web server for WebAuth) for a secondary, more robust authentication process, thus enabling Layer 3 authentication mechanisms.

DConfigure WebAuth so the hosts are redirected to a web page for authentication.

While WebAuth (web authentication) is a Layer 3 authentication mechanism, the action of 'Configure WebAuth' itself is incomplete; it must be integrated with the 802.1X Flexible Authentication feature, often via MAB, to enable the initial network access and redirection from the switch.

Concept tested: 802.1X Flexible Authentication Layer 3 integration

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html

Topics

#802.1X Flexible Authentication#Layer 3 Authentication#MAC Authentication Bypass (MAB)

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice