Wired 802.1X Monitor Mode Command for Minimal Impact

Configure wired network access using 802.1X and IBNS 2.0
Answer Correct answer: C — Configure the authentication open command to enable monitor mode, logging failed authentications without impacting users.

An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?

  1. monitor-mode enabled
  2. authentication host-mode multi-auth
  3. authentication open Correct Answer
  4. pae dot1x enabled

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests IBNS 2.0 monitor mode configuration; the common trap is confusing the descriptive feature name 'monitor mode' with the actual CLI command.

This guide explains how to configure Cisco wired 802.1X monitor mode to log failed authentications in ISE without impacting users. It confirms the 'authentication open' command as the correct configuration.

Choosing 'monitor-mode enabled' (Option A) because it matches the feature name, but the actual valid interface command is 'authentication open'.

Community Discussion (4 comments)

TiberiuszSun 👍 1 Selected: C
If a switchport is in "monitor mode" with the "authentication open" command, then even if ISE sends back a deny or "Access-Reject", the switch will ignore that and still allow traffic to pass. The whole point of "monitor mode" is to see what ISE would allow and not allow. So you can continue to fine-tune your ISE policies. So in ISE, you would see a red deny in the Radius Live Logs, but the switch would not block any traffic for that device. The user or device would not be impacted at all! Then once you are comfortable that ISE is doing what it is supposed to, then you can remove the "authentication open" command from the switchports. Only then will the switch enforce what ISE says.
Korndal 👍 1 Selected: C
Keyword "Command" .......
factmrojas 👍 1 Selected: C
says command!
ZoneHacker 👍 1
For me here it's the answer C. authentication open

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The authentication open command configures a switch port for monitor mode (also known as open mode or low-impact mode). In this state, if 802.1X authentication fails and ISE sends an Access-Reject, the switch logs the failure in ISE but still allows the endpoint traffic to pass. This ensures minimal impact on users during a new deployment while allowing administrators to tune their policies.

Why the Other Options Are Wrong

Option A, monitor-mode enabled, is a distractor that sounds like the feature name but is not a valid Cisco IOS interface command. Option B, authentication host-mode multi-auth, dictates how multiple devices on a single port are authenticated but does not control the port's behavior upon authentication failure. Option D, pae dot1x enabled, simply enables the 802.1X authenticator role on the port but does not configure open/monitor mode behavior.

Community Comment Notes

Commenters correctly identified that the authentication open command allows traffic to pass even upon receiving an Access-Reject from ISE, which is the essence of monitor mode. As TiberiuszSun noted, "even if ISE sends back a deny... the switch will ignore that and still allow traffic to pass." Others emphasized that the question specifically asks for a "command," which helps eliminate distractors that are not valid CLI syntax.

Official Reference

Exam Strategy

When a question asks for a specific command to implement a feature, focus on exact CLI syntax rather than descriptive feature names. For 802.1X monitor mode, remember that 'authentication open' is the required interface command, not variations like 'monitor-mode'.

Related Analysis

← Back to 300-715 Study Guide