Practise switch scenarios involving SW1, SW2, VLANs, trunk links, allowed VLAN lists and show interfaces trunk output.
Start Scenario PracticeCisco ISE is configured with posture assessment to ensure endpoints meet security requirements before gaining network access. After a posture check, ISE needs to dynamically change the VLAN assignment for a non-compliant endpoint. Which ISE feature enables this real-time change?
Explanation: Change of Authorization (CoA) allows ISE to dynamically update authentication and authorization attributes such as VLAN assignment.
In a Cisco ISE deployment, after a device passes posture assessment, ISE needs to dynamically change the VLAN assignment for the device. Which protocol or feature enables ISE to send a new authorization policy to the network access device without requiring the endpoint to reauthenticate?
Explanation: Change of Authorization (CoA) allows ISE to send real-time authorization changes (e.g., VLAN change) to the NAD using RADIUS Disconnect or Change of Authorization messages, without requiring the client to reauthenticate.
An organization uses Cisco ISE to enforce posture compliance. After a user's machine is patched, ISE sends a command to the switch to reclassify the endpoint from a restricted VLAN to a full-access VLAN. Which ISE feature accomplishes this?
Explanation: Change of Authorization (CoA) allows ISE to dynamically change an authenticated session's attributes, such as VLAN assignment or ACL, without requiring reauthentication.
A network administrator is configuring Cisco ISE for posture assessment. A Windows laptop connects to the network and passes 802.1X authentication. ISE then checks if the antivirus software is running and if the OS patches are up to date. If the posture check fails, ISE should dynamically restrict the endpoint to a remediation VLAN. Which mechanism allows ISE to change the VLAN assignment after authentication without requiring the user to reauthenticate?
Explanation: Change of Authorization (CoA) allows ISE to dynamically change the authorization state (e.g., VLAN or ACL) on the network device after the initial authentication. This is used to enforce posture policies without requiring the endpoint to reauthenticate.
An organization is using Cisco ISE to enforce posture compliance. Endpoints that are non-compliant should be placed into a quarantine VLAN. Which ISE policy component is used to assign the VLAN?
Explanation: An Authorization Profile in Cisco ISE defines the enforcement actions to be applied to an endpoint after successful authentication and authorization. When a posture assessment determines an endpoint is non-compliant, the authorization policy can match that condition and return an authorization profile that includes a specific VLAN ID (e.g., quarantine VLAN) via RADIUS attributes such as Tunnel-Private-Group-ID (RFC 2868). This VLAN assignment is a core function of the authorization profile, not of authentication or profiling.
+1 more scenario questions available
Practice all SW1 and SW2 VLAN Trunking Practice QuestionsPractise switch scenarios involving SW1, SW2, VLANs, trunk links, allowed VLAN lists and show interfaces trunk output. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full SW1 and SW2 VLAN Trunking Practice Questions session with instant scoring and detailed explanations.
Start Scenario Practice →