exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 577 discussion

Actual exam question from Cisco's 350-401
Question #: 577
Topic #: 1
[All 350-401 Questions]

An engineer is configuring RADIUS-Based Authentication with EAP MS-CHAPv2 is configured on a client device. Which outer method protocol must be configured on the ISE to support this authentication type?

  • A. LDAP
  • B. EAP-FAST
  • C. EAP-TLS
  • D. PEAP
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kebkim
Highly Voted 2 years, 9 months ago
D. If you use EAP-MSCHAPv2, it means that your clients doesn't need to have a certificate, but your authentication server (NPS) has a certificate. Passwords from the clients are send using hashes to the authentication server. To protect these password hashes being send over the network, you can use PEAP which act as a TLS/SSL tunnel to protect the authentication traffic.
upvoted 15 times
aaabattery
2 years, 2 months ago
https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/201044-802-1x-authentication-with-PEAP-ISE-2-1.html
upvoted 3 times
...
...
Quesocat
Highly Voted 2 years, 6 months ago
Selected Answer: D
EAP Methods That Use Cisco ISE Server Certificate for Authentication -PEAP/EAP-MS-CHAPv2 -PEAP/EAP-GTC -EAP-FAST/EAP-MS-CHAPv2 -EAP-FAST/EAP-GTC https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0100000.html
upvoted 5 times
JoeyT
2 years, 3 months ago
so why C (EAP-FAST) wrong???
upvoted 2 times
Dan_T_P
1 year, 6 months ago
i think because it asks for an "outer" method so would be EAP or PEAP. i think EAP-FAST may count as inner method (based on EAP). Theory only, and ready to be corrected, but makes sense to me.
upvoted 1 times
...
...
...
agabeen
Most Recent 9 months ago
Selected Answer: D
Trust others.. :D
upvoted 1 times
...
[Removed]
1 year ago
Selected Answer: D
D is correct
upvoted 1 times
...
[Removed]
1 year ago
D is correct
upvoted 2 times
...
teems5uk
1 year, 5 months ago
Selected Answer: D
For RADIUS-based authentication with EAP MS-CHAPv2, the appropriate outer method protocol to be configured on the Identity Services Engine (ISE) is PEAP (Protected Extensible Authentication Protocol). PEAP is often used as an outer method to encapsulate the inner EAP (Extensible Authentication Protocol) methods, such as MS-CHAPv2.
upvoted 2 times
...
roonly
1 year, 10 months ago
Selected Answer: D
correct answer is D
upvoted 1 times
...
bob_135
1 year, 11 months ago
Selected Answer: D
Not EAP-TLS definitely. PEAP uses a digital certificate to authenticate the authentication server, but clients need to authenticate themselves through MSCHAPv2 or 2GTC. EAP-TLS goes one step further and requires a certificate on the authentication server and a certificate on every client. The authentication server and supplicant authenticate each other using these certificates. Once authentication is successful, encryption key material is exchanged through the TLS tunnel. EAP-TLS is the most secure method for wireless authentication but can be challenging to implement: You need a Public Key Infrastructure (PKI) to generate certificates. You need to enroll certificates to your clients. When an attacker steals a client device, you need to revoke the certificate.
upvoted 3 times
...
aaabattery
2 years, 2 months ago
Selected Answer: D
https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/201044-802-1x-authentication-with-PEAP-ISE-2-1.html
upvoted 2 times
...
Edwinmolinab
2 years, 7 months ago
Given answer is correct https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/td-p/3540023
upvoted 1 times
...
tckoon
2 years, 8 months ago
Selected Answer: D
correct answer D
upvoted 4 times
...
jj970us
2 years, 9 months ago
Selected Answer: D
Reference: https://social.technet.microsoft.com/Forums/Lync/en-US/7962d24d-7aa2-4413-97da-4f03793f2405/very-confused-on-authenciation-concepts-eap-peap-eapmschapv2-?forum=winserversecurity
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...