A city uses dynamic VLAN assignment via RADIUS after successful staff EAP. What post-authentication capability does that demonstrate?
Select an answer to reveal the explanation.
Short Explanation
After the badge checks out, RADIUS can still say which hallway you get—VLAN or ACL attributes. That is authorization on top of authentication, not 'accept only' and not a substitute for encryption keys.
Full Explanation
RADIUS authorization attributes such as VLAN IDs or filter/ACL references can be applied after successful EAP, placing users into different network postures without separate SSIDs for every role. This is post-auth authorization awareness, not a claim that RADIUS returns only a Boolean, replaces PTK/GTK encryption, or collapses staff users onto an open captive portal.