nerdexam
Cisco

352-001 · Question #344

In a rented office, workers are not assigned to specific cubes. The facility just began to use IEEE 802.1X authentication for the tenants. When workers have previously logged in to a PC, it works…

The correct answer is A. Use machine authentication. Machine authentication allows a PC to authenticate to the 802.1X network before user login, solving the chicken-and-egg problem on previously unused machines with minimal operational overhead.

Designing Security

Question

In a rented office, workers are not assigned to specific cubes. The facility just began to use IEEE 802.1X authentication for the tenants. When workers have previously logged in to a PC, it works correctly, but when they move to another PC that has never been used before, they are unable to log in. Which redesign action will overcome this issue with minimal operational burden?

Options

  • AUse machine authentication.
  • BEstablish a "Bring Your Own Device" portal.
  • CDisable and re-enable network authentication when a new worker logs in to a new machine.
  • DEnable MAC Authentication Bypass.

How the community answered

(38 responses)
  • A
    84% (32)
  • B
    3% (1)
  • C
    8% (3)
  • D
    5% (2)

Why each option

Machine authentication allows a PC to authenticate to the 802.1X network before user login, solving the chicken-and-egg problem on previously unused machines with minimal operational overhead.

AUse machine authentication.Correct

Machine authentication allows the PC itself to present credentials (typically a machine certificate) to the 802.1X authenticator before any user logs in, granting network access so that domain login services and user authentication can succeed on any device in the hot-desking environment, even one that has never been used before.

BEstablish a "Bring Your Own Device" portal.

A BYOD portal addresses personal device onboarding, not the issue of corporate PCs that have never authenticated to the 802.1X infrastructure.

CDisable and re-enable network authentication when a new worker logs in to a new machine.

Disabling and re-enabling port authentication is a manual per-machine workaround that adds significant operational burden and does not scale in a hot-desking environment.

DEnable MAC Authentication Bypass.

MAC Authentication Bypass authenticates devices solely by MAC address, which does not resolve the underlying missing-supplicant-configuration issue on new machines and introduces a security weakness.

Concept tested: IEEE 802.1X machine authentication for hot-desking environments

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-16/sec-usr-8021x-xe-16-book/config-ieee-802x-pba.html

Topics

#802.1X#machine authentication#NAC#network access control

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice