Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network security team is deploying an 802.1X port-based network access control framework across enterprise Ethernet switches. Which of the following statements accurately describe the operational roles and protocol encapsulation methods defined in this framework? (Select TWO)

  1. The network switch functions as the authenticator, relaying EAP messages between the endpoint client and the backend AAA server without evaluating user credentials locally.Cevap
  2. Extensible Authentication Protocol over LAN (EAPOL) carries authentication frames between the supplicant and switch, while EAP over RADIUS carries frames between the switch and AAA server.Cevap
  3. C
    The client endpoint initiates a direct TACACS+ TCP session on port 49 with the central AAA server before port access is granted by the switch.
  4. D
    The authenticator switch decrypts the user credential payload and validates it against its local user database before opening the port.

Cevap

The correct statements are that the network switch functions as an authenticator relaying EAP messages without validating credentials locally, and EAPOL is used between the supplicant and switch while EAP over RADIUS is used between the switch and authentication server.
The 802.1X standard separates access control into three roles: the supplicant (client), the authenticator (switch or wireless access point), and the authentication server (RADIUS). The switch does not evaluate credentials; it simply relays EAP packets. The client communicates with the switch using EAPOL frames, while the switch encapsulates those EAP payloads into RADIUS packets sent to the AAA server over UDP ports 1812/1813.

Adım Adım Çözüm

1
Identify the core components of the IEEE 802.1X architecture.
The architecture defines three entities: Supplicant (client), Authenticator (switch/AP), and Authentication Server (RADIUS).
Understanding component roles clarifies which node processes user credentials.
2
Determine the role of the network switch (authenticator).
The switch acts as a pass-through proxy that holds the port in an unauthorized state, forwarding EAP traffic until authentication succeeds on the RADIUS server.
This confirms that the switch does not validate credentials locally.
3
Analyze protocol encapsulation across the two network links.
Link 1 (Client to Switch) uses EAPOL (EAP over LAN / 802.3 framing). Link 2 (Switch to RADIUS Server) encapsulates EAP inside RADIUS UDP packets.
This confirms the correct transport framing across layer 2 local links and layer 3 backend networks.

Anahtar Kavram

802.1X Framework Roles and EAP Protocol Encapsulation
Bu soruyu puanla