Identity Management, Information Exchange, and Access Control for CCIE Security Written v5.0 (400-251)
This page covers the Identity Management, Information Exchange, and Access Control domain of the CCIE Security Written v5.0 (400-251) certification. Master Cybersecurity offers 33 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which protocol does 802.1X use between the supplicant and the authenticator to authenticate users who wish to access the network?- A. SNMP
- B. TACACS+
- C. RADIUS
- D. EAP over LAN
- E. PPPoE
Explanation
The correct answer is: D. EAP over LAN.
IEEE 802.1X carries authentication exchanges between the supplicant and the authenticator inside EAP over LAN, or EAPOL, which is an Ethernet encapsulation identified by EtherType 0x888E and addressed to the PAE group address 01:80:C2:00:00:03. EAPOL exists precisely because the port is not yet authorized, so no IP address and no routable transport can be assumed; the supplicant may send EAPOL-Start, the authenticator answers with an EAP-Request Identity, and the identity, challenge and result frames all flow as EAPOL-EAP, ending in EAPOL-Success or EAPOL-Failure. RADIUS is the transport on the other side of the authenticator, where the switch relabels the same EAP payloads into the RADIUS EAP-Message attribute 79 toward the authentication server, so it is not used on the supplicant link. TACACS+ over TCP 49 is a device administration protocol for authenticating and authorizing CLI users, not network access ports. SNMP is a management protocol, and PPPoE is a wide area encapsulation used to carry PPP sessions over Ethernet access networks.
Question 2
Which four options are valid EAP mechanisms to be used with WPA2? (Choose four.)- A. PEAP
- B. EAP-TLS
- C. EAP-FAST
- D. EAP-TTLS
- E. EAPOL
- F. EAP-RADIUS
- G. EAP-MD5
Explanation
The correct answers are: A. PEAP, B. EAP-TLS, C. EAP-FAST, D. EAP-TTLS.
WPA2, which implements IEEE 802.11i, requires an EAP method that both authenticates mutually and derives keying material, because the 802.1X exchange must produce a Master Session Key that the authenticator turns into a Pairwise Master Key for the four-way handshake and the resulting CCMP keys. PEAP, EAP-TLS, EAP-FAST and EAP-TTLS all satisfy that: each builds a protected tunnel, authenticates the network to the client through a certificate or a Protected Access Credential, and exports keys, so any of them can be selected as the 802.1X method for a WPA2 Enterprise SSID. EAP-MD5 cannot be used because it is a one-way challenge-response with no server authentication and no key derivation at all, leaving nothing to feed the PMK and no defence against a rogue access point. EAPOL is not a method but the Ethernet-level transport, EtherType 0x888E, that carries EAP between supplicant and authenticator. EAP-RADIUS likewise names the carriage of EAP inside the RADIUS EAP-Message attribute on the link between the access point or controller and the authentication server.
Question 3
Which Cisco ASA feature can be used to update non-compliant antivirus/antispyware definition files on an AnyConnect client?- A. dynamic access policies
- B. dynamic access policies with Host Scan and advanced endpoint assessment
- C. Cisco Secure Desktop
- D. advanced endpoint assessment
Explanation
The correct answer is: B. dynamic access policies with Host Scan and advanced endpoint assessment.
Remediating an out-of-date antivirus or antispyware signature set on an AnyConnect endpoint takes the whole posture chain on the ASA: Host Scan gathers the endpoint facts, Advanced Endpoint Assessment adds the ability to interrogate and then actively update supported antivirus, antispyware and personal firewall products, and a dynamic access policy is the element that inspects the resulting endpoint attributes and selects what happens next. Without a DAP rule matching an attribute such as endpoint.av.mcafeeav.exists or a failed definition-age check, nothing triggers the remediation, so the pieces only produce an update when combined. Advanced Endpoint Assessment on its own is a licensed capability rather than a policy; it needs Host Scan to collect the data and DAP to act on it. Dynamic access policies alone can sort users by AAA and connection attributes and adjust tunnel privileges, but with no posture data they cannot see the signature state. Cisco Secure Desktop is the session containment and cache cleaner framework, which protects data left behind on the host rather than updating definitions.
Question 4
Which three authentication methods does the Cisco IBNS Flexible Authentication feature support? (Choose three.)- A. cut-through proxy
- B. dot1x
- C. MAB
- D. SSO
- E. web authentication
Explanation
The correct answers are: B. dot1x, C. MAB, E. web authentication.
Flexible Authentication in Identity-Based Networking Services exists because a real access port faces a mixture of endpoints: laptops with a supplicant, printers and cameras without one, and guests with a browser. It therefore supports three methods on the same port and lets you sequence them with authentication order and authentication priority. 802.1X is the standards-based method in which the switch relays EAP over LAN frames from the supplicant into RADIUS. MAC Authentication Bypass covers devices with no supplicant by taking a source MAC address learned from the first frame and sending it to RADIUS as both the username and the password, which is why MAB is an authorisation decision made against an inventory list rather than proof of identity. Web authentication, in either the local or centralised form, redirects the first HTTP session to a portal so a human can enter credentials. Cut-through proxy is not a switch feature at all; it is the ASA and PIX mechanism that authenticates a user for Telnet, FTP or HTTP and then permits the rest of the flow in hardware. Single sign-on is a credential reuse concept at the application layer and is not one of the port-based access methods the switch can run.
Question 5
Troubleshooting the web authentication fallback feature on a Cisco Catalyst switch shows that clients with the 802.1X supplicant are able to authenticate, but clients without the supplicant are not able to use web authentication. Which configuration option will correct this issue?- A. switch(config)# aaa accounting auth-proxy default start-stop group radius
- B. switch(config-if)# authentication host-mode multi-auth
- C. switch(config-if)# webauth
- D. switch(config)# ip http server
- E. switch(config-if)# authentication priority webauth dot1x
Explanation
The correct answer is: D. switch(config)# ip http server.
Web authentication on a Catalyst switch is served by the switch internal HTTP process, so ip http server, or ip http secure-server when the login page must be encrypted, is mandatory before any browser-based login can be presented. That neatly explains the symptom: endpoints running a supplicant complete EAPOL and never need a web page, so they authenticate normally, while endpoints with no supplicant fall through to webauth, get intercepted, and then have nothing to talk to because the HTTP listener is not running. Changing the host mode to multi-auth only affects how many independent sessions a port may hold at once, which is unrelated to the missing login page. Setting authentication priority webauth dot1x reorders which method may preempt another and would in fact weaken the intended dot1x-first behaviour. AAA accounting for auth-proxy sends accounting records for sessions that already work rather than creating them. There is also no bare webauth interface command; fallback is configured with authentication fallback pointing at a fallback profile.
Other CCIE Security Written v5.0 (400-251) domains
- Advanced Threat Protection and Content Security (10 questions)
- Infrastructure Security, Virtualization, and Automation (145 questions)
- Perimeter Security and Intrusion Prevention (54 questions)
- Secure Connectivity and Segmentation (87 questions)