300-425 Question 316
Single answerYou are deploying a Cisco access point in a secure enterprise network that requires 802.1X for authentication. The network administrator has asked you to ensure that the access point is authenticated before it is allowed to communicate on the wired network. Which configuration step is required to implement this successfully?
- A
Configure the access point to use a pre-shared key for authentication.
- B
Enable 802.1X on the switch port and configure the access point with EAP-TLS credentials.
- C
Disable 802.1X on the switch port and use MAC authentication bypass (MAB) instead.
- D
Configure the access point to use WPA3 for wireless authentication.
Show answer and explanation
Correct answer: B
Explanation
When deploying Cisco access points in enterprise environments, 802.1X authentication ensures that the access points themselves are authenticated before accessing the wired network. Configuring EAP-TLS credentials on the access point and enabling 802.1X on the switch port is the correct way to implement this. Other methods, such as pre-shared keys or MAB, do not provide the same level of security or meet the requirements for 802.1X-based access point authentication.
- A. Incorrect.
Pre-shared keys are used for wireless client authentication, not for authenticating access points on wired networks.
- B. Correct.
Enabling 802.1X on the switch port and configuring the access point with EAP-TLS credentials ensures the access point can authenticate using a secure 802.1X process before gaining network access.
- C. Incorrect.
Disabling 802.1X and using MAC authentication bypass (MAB) is less secure and does not meet the requirement for 802.1X authentication.
- D. Incorrect.
WPA3 is a wireless security protocol and does not apply to the wired network authentication of an access point.