Be able to choose the correct 802.1X host mode for a given port scenario, read ISE authentication failure reasons, and trace SGT assignment from AD group to TrustSec enforcement. The single most important thing: know that SGT 0 means no tag was assigned, not that access was granted.
Start practicing
Secure Network Access, Visibility and Enforcement — choose a session length
Free · No account required
Domain overview
This domain covers Cisco identity-based access control: 802. 1X, MAB, and web auth on switches and WLCs, Cisco ISE policy sets and authorization profiles, and TrustSec SGTs with SGACL enforcement. Questions are scenario-based troubleshooting of authentication failures, host modes, and SGT assignment, plus configuration choices for wired and wireless access.
Exam objectives
802.1X EAP methods and host modes: single-host, multi-host, multi-domain on switch ports
Cisco ISE policy sets, authentication/authorization rules, and external identity sources like AD
MAB and web authentication fallback for non-supplicant devices such as printers and cameras
TrustSec SGT assignment, static/dynamic mapping, and SGACL enforcement on Catalyst switches
Confusing single-host mode with multi-domain mode; multi-domain allows one data device plus one voice device, not multiple data hosts.
Assuming SGT 0 means authorization succeeded; SGT 0 is the default/unassigned tag, so check AD group mapping and SGT propagation.
Blaming ISE for EAPoL-Start with no EAP-Request/Identity; this often indicates a switch port or supplicant issue, not a policy failure.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is deploying Cisco ISE for guest access. They want to provide a self-service portal where guests can register their devices and receive a temporary username and password. Which ISE component is used to accomplish this?
2A network administrator wants to implement 802.1X on a Cisco switch port for a device that does not support 802.1X. Which feature should be configured to allow the device to connect?
3An organization is using Cisco ISE to enforce posture compliance. Endpoints that are non-compliant should be placed into a quarantine VLAN. Which ISE policy component is used to assign the VLAN?
4A security engineer is configuring Cisco ISE to enforce SGT-based access control. The engineer creates an SGACL on the switch that permits traffic from SGT 10 to SGT 20. However, traffic from SGT 10 to SGT 20 is still being dropped. The engineer verifies that the SGTs are correctly assigned. What is a possible reason for the drop?
5Which THREE of the following are required for a successful 802.1X authentication on a Cisco switch? (Choose THREE)
6Which TWO of the following are features of Cisco TrustSec? (Choose TWO)
7A security architect is designing network access control for a campus network. The requirement is to authenticate users before granting network access and to enforce policies based on user identity and device posture. Which solution should be deployed?
8A company has deployed Cisco ISE for network access control. After a recent upgrade, the operations team notices that some users are being assigned incorrect authorization profiles. The ISE logs show that the users are being matched to the correct identity group, but the authorization result is different from expected. What is the most likely cause?
9Which THREE of the following are valid components of Cisco ISE's visibility and enforcement architecture?
10A network administrator has configured the above on a Cisco switch port for a device that supports both MAB and 802.1X. The device sends an EAPOL-start but the switch responds with an EAP-Request/Identity. The device does not respond to the EAP-Request/Identity. After a timeout, the switch attempts MAB. However, MAB also fails because the RADIUS server does not have the MAC address. Which of the following best describes the final port state?
11Drag and drop the steps to troubleshoot an IPsec VPN failure where Phase 1 is not completing into the correct order.
12Match each Cisco security product to its category.
13An ISE deployment uses TrustSec with SGTs assigned by Active Directory group membership. A group of users in the 'Finance' AD group is correctly receiving SGT 5, but a new user added to that group is getting SGT 0. The ISE policy is unchanged, and other users in the group work fine. What is the most likely cause?
14A network administrator wants to implement 802.1X authentication on a switch port that connects a printer. The printer does not support 802.1X, so the administrator configures MAC Authentication Bypass (MAB) as a fallback method. Which command must be included in the switch port configuration to ensure MAB is attempted after 802.1X times out?
15An engineer is configuring ISE for guest access via a sponsor portal. The policy requires that a sponsor must approve each guest. However, guests are being automatically approved without sponsor interaction. What is the most likely misconfiguration?
16Which TWO are valid methods for determining the SGT (Security Group Tag) assigned to an endpoint in a TrustSec deployment?
17Which THREE are characteristics of Cisco ISE profiler service?
18Refer to the exhibit. A switch port is configured for 802.1X with MAB. The switch has reached its maximum number of authentication sessions (platform limit). When a new device attempts to connect, what happens?
19A network administrator is troubleshooting intermittent authentication failures on a switch port configured for 802.1X with MAB fallback. Users can connect but get dropped after a few minutes. What is the most likely cause?
20An engineer is deploying Cisco ISE for guest access. The guest portal uses a self-provisioned username and password. To ensure secure credential transmission, which protocol should be enforced on the portal?
21An administrator needs to ensure that only authorized hosts can connect to a switch port. The port is connected to a single PC. Which 802.1X host mode should be configured?
22A company is deploying Cisco ISE to enforce access policies based on endpoint posture. Endpoints must be compliant before being granted full network access. Which policy type is used to define the compliance requirements?
23An engineer notices that the 'show authentication sessions' command on a switch shows a session in 'CRITICAL' state. What does this indicate?
24A network administrator wants to centrally manage and enforce access policies for wired and wireless users. Which Cisco product provides this functionality?
25During a security incident, an investigator wants to identify all endpoints that communicated with a known malicious IP address within the last 24 hours. Which Cisco tool is best suited for this forensic analysis?
26A network engineer is implementing Cisco TrustSec. Which two components are required to enforce Security Group Access Control List (SGACL) policies? (Choose two)
27A network engineer configures ISE for 802.1X with PEAP-MSCHAPv2. Users report intermittent authentication failures on certain switches. The engineer checks ISE logs and sees 'Authentication failed' with reason 'User not found in identity store'. What is the most likely issue?
28Which protocol does Cisco ISE use to communicate with the pxGrid controller for sharing contextual data?
29You are troubleshooting a Cisco ISE deployment where some endpoints are stuck in the 'Not Compliant' posture after a posture scan. ISE logs show 'Conditional NAC Agent result: Not Compliant due to missing required application.' The application is installed on the endpoint. What should you check?
30Which Cisco security product provides network visibility and traffic analytics using NetFlow and IPFIX?
31In a Cisco TrustSec deployment, you want to dynamically assign SGTs based on user authentication. Which mechanism should you use?
32Which TWO are common causes for CoA (Change of Authorization) failures in a Cisco ISE deployment? (Choose two.)
33A company uses Cisco ISE for network access control. They have deployed TrustSec and want to enforce segmentation using Security Group Tags (SGTs). The network team reports that SGTs are not being propagated correctly. Which protocol is responsible for SGT propagation between switches?
34The ISE logs show 'Authentication failed - RADIUS attribute Calling-Station-ID is missing' for a wired client. What is the most likely cause?
35A company uses Cisco ISE for posture assessment. They require that all endpoints meet a certain set of compliance rules before being granted network access. Which service is responsible for performing the posture assessment on the endpoint?
36An organization is deploying Cisco TrustSec and uses SXP to propagate SGTs between routers that do not support SGT inline tagging. The SXP connection is established, but the SGT mappings are not being learned. The administrator checks 'show sxp connections' and sees the connection is in 'On' state. What is the most likely issue?
37A network engineer is troubleshooting an 802.1X deployment where some Windows 10 endpoints fail to authenticate. Logs show that the client sends an EAPoL-Start but never receives an EAP-Request/Identity. The switch port configuration is: interface GigabitEthernet0/1 switchport mode access authentication port-control auto dot1x pae authenticator Which additional command is most likely needed?
38A large enterprise uses Cisco ISE with pxGrid to share context with Firepower for threat containment. When a Firepower detects an infected endpoint, it triggers a pxGrid quarantine action that changes the endpoint's authorization profile. The engineer observes that the quarantine is applied, but after the Firepower clears the threat, the endpoint does not regain its original access. What is the most likely reason?
39A university is implementing 802.1X for student wireless networks using Cisco Wireless LAN Controllers (WLCs) and ISE. Students connect with their personal devices using PEAP-MSCHAPv2. During heavy usage, some students report authentication failures and sporadic disconnections. The network team examines the ISE live logs and sees many 'Authentication failed' entries with reason 'Internal error - unable to find a suitable proxy target'. The team has configured two ISE nodes as authentication proxies for the wireless subnets. What is the most likely cause of this issue?
40A multinational corporation is implementing ISE for wired network access using 802.1X with EAP-TLS certificate authentication. Their Windows 10 laptops have certificates issued by an internal PKI. During testing, some users report that they are repeatedly prompted to select a certificate after connecting, and eventually authentication fails. ISE logs show 'Authentication failed - No matching certificate found'. The engineer checks the client machine and sees multiple certificates, including the correct one, in the personal store. The ISE endpoint identity store is populated with the user's AD credentials. What is the most likely cause of this failure?
41A Cisco TrustSec deployment is being implemented to enforce micro-segmentation. The security team needs to ensure that Security Group Tags (SGTs) are propagated across the network. Which THREE methods can be used to distribute SGT information in a TrustSec environment? (Choose three.)
42A network engineer is configuring a Cisco Catalyst switch to enforce 802.1X on a port that connects to an IP phone with a PC daisy-chained behind it. The phone must authenticate first, and then the PC must authenticate separately. Which command sequence correctly enables this behavior on the switch port?
43A network security administrator is deploying Cisco TrustSec in a large enterprise. The company wants to assign Security Group Tags (SGTs) to endpoints based on the VLAN they belong to, without requiring 802.1X authentication. Which Cisco TrustSec feature should the administrator use to accomplish this?
44A network security engineer is configuring TrustSec on Cisco Catalyst switches. The engineer wants to enforce a policy where traffic from the 'Engineering' Security Group (SGT 10) to the 'Finance' Security Group (SGT 20) is denied, while all other inter-group traffic is permitted. The engineer has already configured SGTs and SGACLs on Cisco ISE and downloaded them to the switches. Which additional step is required on the switches to enforce this policy?
45A network administrator is configuring MACsec on a Cisco switch to secure traffic between two switches. The administrator wants to ensure that the MACsec session uses a pre-shared key for authentication. Which MACsec key agreement protocol should be used?
46A security engineer is configuring Cisco ISE to enforce endpoint posture. The requirement is to allow endpoints that have the latest antivirus signature and a specific registry key present. The engineer creates a posture policy with two conditions. However, endpoints that meet only one condition are still being marked compliant. What is the most likely cause?
47A security administrator is deploying Cisco ISE with posture assessment for VPN users. The company uses AnyConnect as the VPN client and ISE for posture policy. After a user connects via VPN, the posture assessment reports the endpoint as non-compliant due to missing antivirus updates. The administrator wants to automatically remediate the endpoint by triggering an antivirus update and then re-assess. Which ISE feature should be configured to achieve this?
48A security administrator is configuring Cisco ISE to enforce endpoint compliance. The administrator wants to ensure that endpoints without the latest antivirus definitions are denied network access. Which ISE policy element should be used to evaluate the antivirus status?
49A network administrator is configuring 802.1X on a Cisco switch. The switch is connected to a Cisco ISE server for authentication. The administrator wants to ensure that if the RADIUS server is unreachable, the switch will place the port in a restricted VLAN instead of denying access. Which command should be configured on the switch port?
50A network administrator is deploying Cisco TrustSec in a mixed-vendor environment. Some switches do not support hardware-based SGT tagging. The administrator needs to propagate SGT information to these switches so that they can enforce SGACLs. Which protocol should be used?
51A security administrator is configuring Cisco ISE to enforce endpoint posture. The policy requires that endpoints must have the latest antivirus definitions and an enabled personal firewall. After a posture assessment, some endpoints are marked as non-compliant but remain in the original VLAN instead of being moved to a remediation VLAN. The administrator has verified that the posture policy conditions are correct and the remediation VLAN is configured. Which action should be taken to ensure non-compliant endpoints are moved to the remediation VLAN?
52A network administrator is deploying Cisco TrustSec in a data center. The requirement is to assign Security Group Tags (SGTs) to traffic based on the source IP address of the endpoint, without relying on 802.1X or any client software. The administrator plans to use a Cisco Identity Services Engine (ISE) and a Cisco Nexus switch as the enforcement point. Which ISE feature should be used to assign SGTs dynamically based on IP address?
53A security engineer is deploying Cisco TrustSec in a large enterprise. The engineer wants to assign Security Group Tags (SGTs) to endpoints based on user identity and device type, and enforce policies across multiple network devices without using VLANs or ACLs on every device. Which component is responsible for propagating the SGT information to network enforcement devices?
54A network administrator is implementing Cisco TrustSec in a campus network. The administrator wants to enforce access policies based on user roles without changing IP addresses or VLANs. Which component of Cisco TrustSec is responsible for tagging packets with Security Group Tags (SGTs)?
55A security engineer is configuring Cisco ISE to enforce endpoint posture compliance. The engineer wants to ensure that endpoints without the latest antivirus definitions are denied network access and placed in a remediation VLAN. After configuring the posture policy, the engineer notices that some non-compliant endpoints are still granted full access. The engineer verifies that the posture policy conditions are correct and that the endpoints are being profiled correctly. Which action should the engineer take to resolve this issue?
56A security administrator is configuring Cisco ISE to monitor endpoints connecting to the network. The goal is to create a report that shows all endpoints that have connected in the past 30 days, including their MAC addresses, IP addresses, and operating systems. Which ISE feature should be used to generate this report?
57A network administrator is configuring 802.1X on a Cisco switch. The switch is configured for single-host mode. A user connects a small unmanaged switch to the 802.1X-enabled port and attaches three devices. Only the first device authenticates successfully; the other devices cannot access the network. What is the most likely reason?
58A security administrator is configuring Cisco ISE to support BYOD onboarding. The administrator wants to ensure that employee personal devices are automatically registered and provisioned with the necessary certificates. Which ISE feature should be used?
59A network administrator is deploying Cisco TrustSec in a campus network. The administrator needs to enforce access policies based on Security Group Tags (SGTs) between endpoints. Which two statements about SGT enforcement are true? (Choose two.)
60A network security engineer is deploying Cisco Stealthwatch to detect anomalies in a large enterprise network. The engineer needs to ensure that Stealthwatch can analyze traffic from all endpoints, including those in remote branch offices that do not have a local Stealthwatch Flow Collector. Which deployment option should be used to meet this requirement?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to choose the correct 802.1X host mode for a given port scenario, read ISE authentication failure reasons, and trace SGT assignment from AD group to TrustSec enforcement. The single most important thing: know that SGT 0 means no tag was assigned, not that access was granted.
The Courseiva 350-701 question bank contains 60 questions in the Secure Network Access, Visibility and Enforcement domain, covering the 15% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Secure Network Access, Visibility and Enforcement domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included