350-401 exam dumps

350-401 practice question 304 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 304

Select 3

A network administrator is configuring access control on a switch for a corporate office. The goal is to authenticate users connecting to the network via wired connections by requiring them to provide valid credentials. However, some legacy devices, such as printers, do not support 802.1X authentication. The administrator also wants to enable guest access for non-employee devices using a web portal. Which combination of network access control methods should the administrator implement to meet these requirements?

  1. A

    802.1X for user authentication

  2. B

    MAC Authentication Bypass (MAB) for legacy devices

  3. C

    WebAuth for guest access

  4. D

    Port security with static MAC addresses for all devices

  5. E

    802.1X for guest access instead of WebAuth

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the requirements, the administrator should use 802.1X to authenticate users with valid credentials, MAB for legacy devices that cannot perform 802.1X authentication, and WebAuth to enable guest access via a web portal. This combination ensures secure access for employees, support for legacy devices, and a simple onboarding process for guest users. Port security is too rigid for this environment, and 802.1X is not appropriate for guest access.

  • A. Correct.

    802.1X is the preferred method for authenticating users connecting to the network with valid credentials, such as employees using laptops or desktops.

  • B. Correct.

    MAC Authentication Bypass (MAB) allows devices that do not support 802.1X (e.g., printers or other legacy devices) to authenticate based on their MAC address.

  • C. Correct.

    WebAuth is typically used to provide guest access through a web portal, allowing non-employees to connect to the network after providing appropriate details.

  • D. Incorrect.

    Port security with static MAC addresses is not scalable or flexible in this scenario, as it would require manual configuration of MAC addresses for all devices, including guest devices and legacy devices.

  • E. Incorrect.

    802.1X is not suitable for guest access because guest devices often do not have the necessary credentials or configuration required for 802.1X authentication.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam