Which component must be the 802.1X authenticator with autonomous APs?
An engineer deploys APs in autonomous mode to provide corporate and guest access in several retail locations. Remote authentication with IEEE 802.1X is configured to ensure a secure wireless connection for corporate users. Which component must be configured as the authenticator?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the three roles of 802.1X (supplicant, authenticator, authentication server) and the trap of confusing the authenticator with the RADIUS-based authentication server.
When autonomous APs serve corporate and guest WLANs with IEEE 802.1X, the AP itself acts as the authenticator in the 802.1X framework. This page confirms that the autonomous AP, not the RADIUS server, the authentication server, or the supplicant, is the device configured as the authenticator.
The most common wrong answer is A (RADIUS server) or B (authentication server), because learners conflate the server that validates credentials with the network device that enforces port access; in 802.1X the RADIUS server is only the authentication server, while the autonomous AP is the authenticator.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In IEEE 802.1X, the authenticator is the network access device that controls the logical port and relays EAP messages between the supplicant and the authentication server. With autonomous APs, each AP terminates the wireless client association and performs that role, so the AP must be configured as the authenticator (typically pointing to the RADIUS server as the authentication server). The question explicitly places the engineer in autonomous mode with 802.1X for corporate users, which is exactly the scenario where the AP itself handles 802.1X authentication. Therefore option C is the correct component to configure as the authenticator.Why the Other Options Are Wrong
Option A (RADIUS server) is the authentication server: it validates user credentials and returns Accept/Reject, but it does not sit in the data path or control the client port. Option B (authentication server) is the same 802.1X role as the RADIUS server and is not the authenticator. Option D (supplicant) is the client device such as a laptop or phone that requests access; it never authenticates the network. Only the AP matches the authenticator definition in an autonomous wireless deployment.Community Comment Notes
Community consensus is unanimous: every recorded vote selected option C, and Le91 succinctly stated "AP is right answer". As rrahim explained, the framework has three components and described the authenticator as "Authenticator: The network device (e.g., an AP or switch)". MaxMusti also noted that the provided answer is correct. These comments reinforce the standard 802.1X role mapping rather than adding any contradictory evidence.Exam Tip
On 300-430, identify the 802.1X role before choosing an option: the supplicant asks, the authenticator enforces, and the authentication server decides. If the question mentions autonomous APs, the AP is the authenticator by default because it terminates client associations and talks to the RADIUS server.Exam Strategy
Memorize the 802.1X triad as supplicant, authenticator, and authentication server, then match each option to its role in the scenario. In autonomous AP questions, the AP is almost always the authenticator because it is the network device controlling client access.
Frequently Asked Questions
Why isn't the RADIUS server the authenticator in this 802.1X scenario?
In 802.1X the RADIUS server is the authentication server that validates credentials; the authenticator is the network access device, here the autonomous AP, that controls the client port.
What role does the supplicant play with autonomous APs and 802.1X?
The supplicant is the client device, such as a laptop or phone, that requests network access and passes credentials through the AP to the RADIUS server.