skip to content

NAC & 802.1X

You will learn how 802.1X authenticates devices at the port using EAP methods over RADIUS, how MAB handles agentless devices, and how NAC platforms assign VLANs and check endpoint posture dynamically. Interviewers probe the supplicant–authenticator–server flow because it ties authentication, switching, and policy together.

on this pageshow

explore

questions

page 2 of 2

What proves a DHCP binding table is complete before validation drops, and who signs for the ports where a host can still claim the gateway?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Nothing inside the table proves it. Reconcile against sources it did not build: server leases, switch MAC tables, router neighbour caches, the inventory of hosts that never lease. What stays unmatched becomes a static binding or a signed exemption.

open as a page

802.1X enforcement day: how do you get an owner to sign fail-open, admitting whoever is in the cabinet, or fail-closed, a site dark for a day?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Take it to whoever owns the sites, not the security team. Price a realistic outage per site class against what an open port reaches, recommend a different posture per class, and get the choice, the back-out and the invoker named on the change record before enforcement.

open as a page

showing 31–32 of 32