Optimize your success on the FSNA Readiness Exam. Engage with flashcards and multiple choice questions, each designed with hints and explanations. Prepare thoroughly for your test and excel!

Multiple Choice

Which authentication mechanism can be enabled on switches to prevent network access until the host/user has authenticated with the authentication server?

This question is about controlling access at the switch port through port-based authentication. With 802.1X enabled, a switch acts as the authenticator and keeps the port in an unauthorized state until the connected host (the supplicant) proves its identity to an authentication server using an EAP method. The server, typically backed by a RADIUS system, validates the credentials; once approved, the switch moves the port to an authorized state and traffic is allowed. LDAP is a directory service protocol, not a mechanism for on-switch access control; RADIUS is the server-side protocol used during the 802.1X process, but the enforcing mechanism on the switch is 802.1X; MAC Authentication Bypass is a fallback option that can allow access based on MAC without full 802.1X, but it doesn’t provide the same controlled, authenticated access flow. Therefore, the switch-based mechanism that prevents network access until authentication is 802.1X.

This question is about controlling access at the switch port through port-based authentication. With 802.1X enabled, a switch acts as the authenticator and keeps the port in an unauthorized state until the connected host (the supplicant) proves its identity to an authentication server using an EAP method. The server, typically backed by a RADIUS system, validates the credentials; once approved, the switch moves the port to an authorized state and traffic is allowed. LDAP is a directory service protocol, not a mechanism for on-switch access control; RADIUS is the server-side protocol used during the 802.1X process, but the enforcing mechanism on the switch is 802.1X; MAC Authentication Bypass is a fallback option that can allow access based on MAC without full 802.1X, but it doesn’t provide the same controlled, authenticated access flow. Therefore, the switch-based mechanism that prevents network access until authentication is 802.1X.