Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-715 Exam - Topic 7 Question 54 Discussion

An engineer is configuring 802.1X and is testing out their policy sets. After authentication, some endpoints are given an access-reject message but are still allowed onto the network. What is causing this issue to occur?
D) The switch port is configured with authentication open.
A) The switch port is configured with authentication event server dead action authorize vlan.
B) The authorization results for the endpoints include a dACL allowing access.
C) The authorization results for the endpoints include the Trusted security group tag.

Cisco 300-715 Exam - Topic 7 Question 54 Discussion

Actual exam question for Cisco's 300-715 exam
Question #: 54
Topic #: 7
[All 300-715 Questions]

An engineer is configuring 802.1X and is testing out their policy sets. After authentication, some endpoints are given an access-reject message but are still allowed onto the network. What is causing this issue to occur?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Sue
10 months ago
Not sure about that, could be a bug in the system too.
upvoted 0 times
...
Melodie
10 months ago
Option B is probably the culprit here, dACLs can be tricky.
upvoted 0 times
...
Gilberto
10 months ago
Wait, how can they be rejected but still get on the network?
upvoted 0 times
...
Rosio
11 months ago
I think it's definitely option A. That makes sense!
upvoted 0 times
...
Katy
11 months ago
Sounds like a classic case of misconfigured switch ports.
upvoted 0 times
...
Aretha
11 months ago
I feel like option D, authentication open, could be a possibility too. It seems like it would let devices connect regardless of the reject status.
upvoted 0 times
...
Brigette
11 months ago
I vaguely recall a similar question where the Trusted security group tag was involved. Could that be option C here?
upvoted 0 times
...
Tony
11 months ago
I think it might be option B because if the dACL allows access, that could explain why they're still on the network despite the reject message.
upvoted 0 times
...
Emile
11 months ago
I remember something about the switch port configuration affecting access, but I'm not sure if it's option A or D.
upvoted 0 times
...
Curt
11 months ago
I feel pretty confident that the answer is B. The forwarding profile is all about how the SD-WAN matches and routes traffic, so that definition of the criteria for matching traffic makes the most sense to me.
upvoted 0 times
...
Beckie
11 months ago
This question seems straightforward, but I want to make sure I understand the key concepts of diversity, inclusion, and equality before selecting my answers.
upvoted 0 times
...
Emerson
11 months ago
I think I recall something about group versus individual plans being a distinction, but I'm not sure if it's the main factor they wanted us to focus on here.
upvoted 0 times
...

Save Cancel