exam questions

Exam 300-430 All Questions

View all questions & answers for the 300-430 exam

Exam 300-430 topic 1 question 99 discussion

Actual exam question from Cisco's 300-430
Question #: 99
Topic #: 1
[All 300-430 Questions]

An engineer has implemented 802.1x authentication on the wireless network utilizing the internal database of a RADIUS server. Some clients reported that they are unable to connect. After troubleshooting, it is found that PEAP authentication is failing. A debug showed the server is sending an Access-Reject message.
Which action must be taken to resolve authentication?

  • A. Use the user password that is configured on the server.
  • B. Disable the server certificate to be validated on the client.
  • C. Update the client certificate to match the user account.
  • D. Replace the client certificates from the CA with the server certificate.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rrahim
1 week ago
Selected Answer: A
A. Use the user password that is configured on the server. Explanation: PEAP Authentication Failure: PEAP (Protected Extensible Authentication Protocol) uses a server certificate to establish a secure TLS tunnel, but the actual user authentication is performed using credentials (username and password) stored in the RADIUS server's internal database. If the RADIUS server sends an Access-Reject message, it indicates that the user credentials provided by the client do not match those configured on the server. Root Cause: The most common reason for an Access-Reject message during PEAP authentication is an incorrect username or password. The client may be providing credentials that do not match those stored in the RADIUS server's internal database. Solution: Ensure that the client is using the correct username and password as configured on the RADIUS server. This will resolve the authentication failure.
upvoted 1 times
...
GOfeni
3 months, 3 weeks ago
Selected Answer: A
PEAP is a Tunnel Method that only validates the Server certificate. Since the question mentions "the server is sending an Access-Reject message", it is understood the Server certificate has been validated successfully (therefore B is incorrect). The question does not explicitly mention what Inner Method is being used, however it mentions the "internal database of a RADIUS server" is being used for Authentication, this means Username and Password are configured locally on the RADIUS server, since certificates are not supported with Internal Database (therefore C and D are incorrect). In this case, some clients are using the wrong user password, and they need to use the password that have been configured on the server to solve the issue.
upvoted 1 times
...
[Removed]
1 year, 4 months ago
Here is a quote from the Cisco documentation: If PEAP authentication is failing and the server is sending an Access-Reject message, it is likely that the client certificate is not valid or does not match the user account. To resolve the issue, you can update the client certificate to match the user account. You can do this by using a certificate enrollment system or by manually installing the client certificate on the client device.
upvoted 1 times
[Removed]
1 year, 4 months ago
According to the Cisco documentation, the best solution to the problem is (C) Update the client certificate to match the user account.
upvoted 1 times
...
...
Ace_Pee
1 year, 8 months ago
RADIUS wont send an access reject if the certs are invalid if using PEAP mschapv2
upvoted 1 times
...
Zanjit500
1 year, 8 months ago
The server is not trusting the client, not the other way around. Hence D.
upvoted 1 times
...
NoWiresIncluded
1 year, 8 months ago
Selected Answer: D
Disabling the Server Certificate check will work (B), but then you are not using PEAP, you are back to LEAP, and you have removed all the security benefits of that cert. You need to reload the server certifcate onto the clients that are failing. Choice D.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago