Correct Answer: EAP-TLS or PEAP with strong inner methods for user/device authentication, MAB as a controlled fallback for non-802.1X devices, dynamic VLAN/authorization assignment via RADIUS attributes, and redundant PSNs for authentication availability
Explanation: Strong EAP methods, a controlled MAB fallback, RADIUS-based dynamic authorization, and redundant PSNs together provide secure, resilient wireless 802.1X, unlike a campus-wide shared PSK with no 802.1X, no fallback for incapable devices, missing RADIUS attribute support for VLAN assignment, a single non-redundant PSN, or disabling authentication logging.
Correct Answer: EAP-TLS or PEAP with strong inner methods for user/device authentication, MAB as a controlled fallback for non-802.1X devices, dynamic VLAN/authorization assignment via RADIUS attributes, and redundant PSNs for authentication availability
Explanation: Strong EAP methods, a controlled MAB fallback, RADIUS-based dynamic authorization, and redundant PSNs together provide secure, resilient wireless 802.1X, unlike a campus-wide shared PSK with no 802.1X, no fallback for incapable devices, missing RADIUS attribute support for VLAN assignment, a single non-redundant PSN, or disabling authentication logging.