Which Protocol Supports Certificate Authentication and Device Quarantine?
A systems administrator is redesigning how devices will perform network authentication. The following requirements need to be met: • An existing internal certificate must be used. • Wired and wireless networks must be supported. • Any unapproved device should be isolated in a quarantine subnet. • Approved devices should be updated before accessing resources. Which of the following would best meet the requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests 802.1X as the foundational NAC framework while trapping candidates who confuse it with underlying components like EAP or RADIUS.
This question tests port-based network access control using 802.1X for unified wired and wireless authentication. The explanation clarifies why 802.1X uniquely satisfies certificate integration, device quarantine, and compliance enforcement compared to standalone protocols.
Candidates often select RADIUS or EAP because they handle authentication, but these lack the built-in port-level access control and policy enforcement required for device quarantine and compliance checking.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
802.1X is the IEEE standard for port-based network access control, making it the definitive choice for this scenario. It natively supports both wired and wireless connections, leverages internal PKI certificates through EAP-TLS, and serves as the foundation for integrating with Network Access Control (NAC) solutions. These integrations enforce the required policies for isolating unapproved devices into quarantine subnets and mandating updates before resource access.Why the Other Options Are Wrong
EAP is merely an authentication framework that operates within 802.1X and does not manage port-level access or device compliance. RADIUS functions as the backend authentication server that validates credentials but lacks the inherent capability to isolate non-compliant endpoints or enforce pre-access updates. WPA2 is exclusively a wireless security protocol and cannot satisfy the requirement for wired network support.Community Comment Notes
Learners overwhelmingly selected 802.1X, correctly recognizing it as the comprehensive framework rather than isolated components. As user brf2017 observed, "All answers provide some authentication but the best answer would be 802.1x" because only it fulfills every stated condition. Multiple verified test-takers confirmed that understanding 802.1X as the NAC backbone resolves the distractor confusion.Exam Strategy
Focus on distinguishing the access control framework from its supporting protocols when reviewing Security+ practice questions. Memorize that 802.1X manages the physical or logical port state, while RADIUS and EAP simply validate credentials behind the scenes.
Frequently Asked Questions
Why isn't RADIUS the correct answer for network authentication here?
RADIUS handles backend authentication and accounting but lacks the port-level access control and policy enforcement required for device quarantine and compliance checks.
How does 802.1X work with internal certificates for authentication?
802.1X uses EAP-TLS to exchange internal PKI certificates between the supplicant and authenticator, ensuring mutual authentication before granting network access.