Which component must be the 802.1X authenticator with autonomous APs?

Implement client security on different wireless architectures and ISE
Answer Correct answer: C — The autonomous AP is the 802.1X authenticator, relaying EAP between the supplicant and the RADIUS authentication server.

An engineer deploys APs in autonomous mode to provide corporate and guest access in several retail locations. Remote authentication with IEEE 802.1X is configured to ensure a secure wireless connection for corporate users. Which component must be configured as the authenticator?

  1. RADIUS server
  2. authentication server
  3. APs Correct Answer
  4. supplicant

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the three roles of 802.1X (supplicant, authenticator, authentication server) and the trap of confusing the authenticator with the RADIUS-based authentication server.

When autonomous APs serve corporate and guest WLANs with IEEE 802.1X, the AP itself acts as the authenticator in the 802.1X framework. This page confirms that the autonomous AP, not the RADIUS server, the authentication server, or the supplicant, is the device configured as the authenticator.

The most common wrong answer is A (RADIUS server) or B (authentication server), because learners conflate the server that validates credentials with the network device that enforces port access; in 802.1X the RADIUS server is only the authentication server, while the autonomous AP is the authenticator.

Community Discussion (3 comments)

rrahim 👍 1 Selected: C
n an IEEE 802.1X authentication framework, there are three main components: Supplicant: The client device (e.g., a laptop or smartphone) requesting access to the network. Authenticator: The network device (e.g., an AP or switch) that controls access to the network and acts as an intermediary between the supplicant and the authentication server. Authentication Server: Typically a RADIUS server, which verifies the credentials of the supplicant and informs the authenticator whether to grant or deny access. Since the APs are deployed in autonomous mode and are responsible for enforcing network access control, they must act as the authenticator in the 802.1X process. The APs will relay authentication requests from the supplicant (corporate users) to the RADIUS server (authentication server) and enforce the access decision.
Le91 👍 1 Selected: C
AP is right answer
MaxMusti 👍 1
provided answer is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In IEEE 802.1X, the authenticator is the network access device that controls the logical port and relays EAP messages between the supplicant and the authentication server. With autonomous APs, each AP terminates the wireless client association and performs that role, so the AP must be configured as the authenticator (typically pointing to the RADIUS server as the authentication server). The question explicitly places the engineer in autonomous mode with 802.1X for corporate users, which is exactly the scenario where the AP itself handles 802.1X authentication. Therefore option C is the correct component to configure as the authenticator.

Why the Other Options Are Wrong

Option A (RADIUS server) is the authentication server: it validates user credentials and returns Accept/Reject, but it does not sit in the data path or control the client port. Option B (authentication server) is the same 802.1X role as the RADIUS server and is not the authenticator. Option D (supplicant) is the client device such as a laptop or phone that requests access; it never authenticates the network. Only the AP matches the authenticator definition in an autonomous wireless deployment.

Community Comment Notes

Community consensus is unanimous: every recorded vote selected option C, and Le91 succinctly stated "AP is right answer". As rrahim explained, the framework has three components and described the authenticator as "Authenticator: The network device (e.g., an AP or switch)". MaxMusti also noted that the provided answer is correct. These comments reinforce the standard 802.1X role mapping rather than adding any contradictory evidence.

Exam Tip

On 300-430, identify the 802.1X role before choosing an option: the supplicant asks, the authenticator enforces, and the authentication server decides. If the question mentions autonomous APs, the AP is the authenticator by default because it terminates client associations and talks to the RADIUS server.

Exam Strategy

Memorize the 802.1X triad as supplicant, authenticator, and authentication server, then match each option to its role in the scenario. In autonomous AP questions, the AP is almost always the authenticator because it is the network device controlling client access.

Frequently Asked Questions

Why isn't the RADIUS server the authenticator in this 802.1X scenario?

In 802.1X the RADIUS server is the authentication server that validates credentials; the authenticator is the network access device, here the autonomous AP, that controls the client port.

What role does the supplicant play with autonomous APs and 802.1X?

The supplicant is the client device, such as a laptop or phone, that requests network access and passes credentials through the AP to the RADIUS server.

Related Analysis

← Back to 300-430 Study Guide