nerdexam
Cisco

352-001 · Question #388

You are designing an IEEE 802.1X solution for a customer, where the network supports a large number of IP phones and printers. You plan to configure MAC address bypass for the phones and printers…

The correct answer is C. the potential of MAC address spoofing. MAC Authentication Bypass (MAB) uses the device MAC address as the sole credential, making MAC address spoofing the primary security concern because an attacker can clone an authorized device's MAC to gain network access.

Designing Security

Question

You are designing an IEEE 802.1X solution for a customer, where the network supports a large number of IP phones and printers. You plan to configure MAC address bypass for the phones and printers. What is your primary design and security concern?

Options

  • Athe additional AAA traffic on the network
  • Bthe placement of the AAA server
  • Cthe potential of MAC address spoofing
  • Dthe scaling of the MAC address database

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    82% (46)
  • D
    11% (6)

Why each option

MAC Authentication Bypass (MAB) uses the device MAC address as the sole credential, making MAC address spoofing the primary security concern because an attacker can clone an authorized device's MAC to gain network access.

Athe additional AAA traffic on the network

Additional AAA RADIUS traffic is a general scalability concern for any 802.1X deployment and is not specific to the security risk introduced by using MAB for phones and printers.

Bthe placement of the AAA server

AAA server placement is an architectural redundancy and latency concern that applies to all 802.1X designs, not a unique security risk posed by MAB specifically.

Cthe potential of MAC address spoofingCorrect

MAB authenticates devices purely by MAC address, which is trivially spoofable using common OS tools; an attacker who observes an authorized IP phone or printer MAC address on the wire can reprogram their NIC to impersonate that device and bypass 802.1X entirely, gaining the same network access as the legitimate device.

Dthe scaling of the MAC address database

Scaling the MAC address database is an operational concern related to managing authorized endpoints, but it does not represent a security vulnerability inherent to the MAB authentication method.

Concept tested: 802.1X MAC Authentication Bypass security risks

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html

Topics

#802.1X#MAC address bypass#MAC spoofing#AAA

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice