Question 1
Q1A financial services firm is deploying Meraki MS390 switches and needs to enforce strict, identity-based access control for all wired connections. The security policy requires that devices are authenticated via EAP-TLS using machine certificates, and if a device fails authentication, it must be placed into a quarantine VLAN for remediation. Which configuration item is the most critical component for dynamically assigning the quarantine VLAN to non-compliant devices?
Show answer & explanation
Correct answer: C
The RADIUS server is responsible for the authentication decision. For dynamic VLAN assignment, the server sends specific RADIUS attributes (like Tunnel-Private-Group-ID) in the Access-Accept or Access-Reject message to instruct the switch which VLAN to place the client in. If authentication fails, the RADIUS server can be configured to send back an Access-Accept message that still assigns the device to the specified quarantine VLAN, effectively isolating it.