NAC & 802.1X
You will learn how 802.1X authenticates devices at the port using EAP methods over RADIUS, how MAB handles agentless devices, and how NAC platforms assign VLANs and check endpoint posture dynamically. Interviewers probe the supplicant–authenticator–server flow because it ties authentication, switching, and policy together.
on this pageshowhide
explore
- Admitting a Device20 questions
- The Port Asks First4 questions
- Enrolment Bounds the Programme4 questions
- Printers and Cameras4 questions
- Admission Without a Cable4 questions
- Ports in Public Places4 questions
- The Day It Denies12 questions
- Trusting the First Switch4 questions
- Locking Out the Estate4 questions
- Quarantine Needs a Route4 questions
questions
page 2 of 2What proves a DHCP binding table is complete before validation drops, and who signs for the ports where a host can still claim the gateway?
basics
~20 sNothing inside the table proves it. Reconcile against sources it did not build: server leases, switch MAC tables, router neighbour caches, the inventory of hosts that never lease. What stays unmatched becomes a static binding or a signed exemption.
802.1X enforcement day: how do you get an owner to sign fail-open, admitting whoever is in the cabinet, or fail-closed, a site dark for a day?
basics
~20 sTake it to whoever owns the sites, not the security team. Price a realistic outage per site class against what an open port reaches, recommend a different posture per class, and get the choice, the back-out and the invoker named on the change record before enforcement.
showing 31–32 of 32