exam questions

Exam 300-208 All Questions

View all questions & answers for the 300-208 exam

Exam 300-208 topic 1 question 226 discussion

Actual exam question from Cisco's 300-208
Question #: 226
Topic #: 1
[All 300-208 Questions]

Which packets are allowed on a dot1x port with no authentication open before the port goes to an authorized state?

  • A. CDP, EAPOL, STP
  • B. CDP, DHCP, DNS
  • C. DHCP, EAPOL, HTTP
  • D. CDP, EAPOL, HTTP
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
memes
5 years, 10 months ago
The 802.1x standard defines a client-server-based access control and authentication protocol that prevents unauthorized clients from connecting to a LAN through publicly accessible ports unless they are properly authenticated. The authentication server authenticates each client connected to a switch port before making available any services offered by the switch or the LAN. Until the client is authenticated, 802.1x access control allows only Extensible Authentication Protocol over LAN (EAPOL), Cisco Discovery Protocol (CDP), and Spanning Tree Protocol (STP) traffic through the port to which the client is connected. After authentication is successful, normal traffic can pass through the port.
upvoted 1 times
...
denno
5 years, 10 months ago
The correct answer here is A. The port starts in the unauthorized state. While the port is in this state, the port that is not configured as a voice VLAN port disallows all ingress and egress traffic except for 802.1X, Cisco Discovery Protocol, and STP packets. When a client is successfully authenticated, the port changes to the authorized state and allows all traffic for the client to flow normally. If the port is configured as a voice VLAN port, the port allows VoIP traffic and 802.1X protocol packets before the client is successfully authenticated. If a client that does not support 802.1X connects to an unauthorized 802.1X port, the switch requests the identity of the client. In this situation, if the client does not respond to the request, the port remains in the unauthorized state, and the client is not granted access to the network. See Page 9-4: https://www.cisco.com/c/en/us/td/docs/switches/metro/me3400e/software/release/12-2_55_se/configuration/guide/ME3400e_scg/sw8021x.pdf
upvoted 2 times
evdw
5 years, 5 months ago
Agree A
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...