Autonomous AP 802.1X: Which Two RADIUS Details Must Be Configured?

Implement client security on different wireless architectures and ISE
Answer Correct answer: C, D — Configure the RADIUS server IP address and matching shared secret on the autonomous AP so it can forward 802.1X user authentication requests.

An engineer needs to configure an autonomous AP for 802.1x authentication. To achieve the highest security an authentication server is used for user authentication. During testing, the AP fails to pass the user authentication request to the authentication server. Which two details need to be configured on the AP to allow communication between the server and the AP? (Choose two.)

  1. username and password
  2. PAC encryption key
  3. RADIUS IP address Correct Answer
  4. shared secret Correct Answer
  5. group name

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests RADIUS client configuration on an autonomous AP; the trap is choosing user credentials or EAP-FAST PAC parameters instead of the server address and shared secret.

An autonomous AP must act as a RADIUS client for 802.1X user authentication. This page confirms that the RADIUS server IP address and shared secret are the two required details.

Selecting username/password (A) because it sounds like authentication; these are for AP management or supplicant credentials, not for AP-to-RADIUS communication.

Community Discussion (3 comments)

rrahim 👍 1 Selected: CD
To allow communication between the autonomous AP and the RADIUS (authentication) server for 802.1X authentication, the following details must be configured on the AP: C. RADIUS IP address: The AP needs to know the IP address of the RADIUS server to send authentication requests. D. shared secret: The shared secret is a pre-shared key configured on both the AP and the RADIUS server to secure the communication between them. It ensures that the AP and the RADIUS server can trust each other.
Le91 👍 1
correct
MaxMusti 👍 1
provided answer is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The autonomous AP must act as a RADIUS client when it forwards 802.1X user authentication requests to the external authentication server. For that communication to work, the AP needs the RADIUS server's IP address so it knows where to send Access-Request packets, and it needs the shared secret that must match the secret configured on the RADIUS server. In Cisco autonomous AP configuration, these are the core RADIUS server parameters under the security or services RADIUS settings. Without either one, the AP cannot establish a trusted RADIUS exchange and the user authentication request never reaches the server. Therefore options C and D are the two required details.

Why the Other Options Are Wrong

A username and password are used for AP management access or for an 802.1X supplicant identity, not for the RADIUS client-to-server authentication exchange, so option A does not solve the failed forwarding. The PAC encryption key in option B is associated with EAP-FAST provisioning and tunnel establishment, not with basic RADIUS server reachability for 802.1X user authentication. Option E, group name, may appear in AAA server group configuration, but it is not the detail that enables communication between the AP and the authentication server. Only the server IP address and the matching shared secret directly allow the AP to pass authentication requests to the RADIUS server.

Community Comment Notes

As rrahim explained, the AP needs the RADIUS IP address to send authentication requests and the shared secret to secure communication with the server, and both must match what is configured on the RADIUS server. Le91 and MaxMusti also marked the provided answer as correct, reinforcing the CD consensus. No commenter argued for username/password, PAC key, or group name as the missing communication details. The community discussion aligns with the standard RADIUS client requirements for autonomous AP 802.1X deployments.

Exam Strategy

When the stem asks what allows the AP to communicate with the authentication server, focus on RADIUS client parameters: server IP address and shared secret. User credentials and EAP-FAST PAC settings are distractors because they do not establish the AP-to-RADIUS transport.

Frequently Asked Questions

Why is the PAC encryption key not needed for autonomous AP 802.1X?

PAC is used with EAP-FAST for tunnel establishment; standard 802.1X RADIUS client communication only needs the server IP and shared secret.

Does the AP need a username and password for RADIUS authentication?

No. Those are for the AP's management login or an 802.1X supplicant, not for the AP-to-RADIUS server authentication exchange.

Related Analysis

← Back to 300-430 Study Guide