These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.
Start Scenario PracticeAn administrator is troubleshooting authentication failures for VPN users. The RADIUS server is reachable via ping, but users receive 'AAA authentication failed'. Which command should be used to test communication with the RADIUS server?
Explanation: The 'test aaa group radius user password' command is specifically designed to simulate an authentication attempt against a RADIUS server, allowing the administrator to verify whether the RADIUS server is properly processing credentials. Since the RADIUS server is reachable via ping but users still fail, this command isolates whether the issue lies in the AAA authentication process itself, such as incorrect shared secret, user credentials, or RADIUS attribute mismatches.
A network engineer is troubleshooting an 802.1X deployment where some Windows 10 endpoints fail to authenticate. Logs show that the client sends an EAPoL-Start but never receives an EAP-Request/Identity. The switch port configuration is: interface GigabitEthernet0/1 switchport mode access authentication port-control auto dot1x pae authenticator Which additional command is most likely needed?
Explanation: The command dot1x system-auth-control is a global configuration command that enables 802.1X authentication on the switch. Without it, the per-interface dot1x pae authenticator and authentication port-control auto commands have no effect because the 802.1X process is not globally enabled. This is why the client sends EAPoL-Start but the switch never responds with EAP-Request/Identity.
A security analyst wants to investigate a remote endpoint that is suspected of being compromised. Using Cisco AMP for Endpoints, which capability allows the analyst to run commands on the endpoint and perform live analysis?
Explanation: Cisco AMP for Endpoints includes endpoint detection and response (EDR) capabilities such as remote shell, which allows analysts to execute commands on the endpoint for investigation.
An engineer is troubleshooting a Cisco ASA firewall and notices that traffic from a specific subnet is being dropped. The engineer wants to verify if the drop is due to an access control list (ACL) or an inspection policy. Which command should be used to see the reason for packet drops?
Explanation: The 'show asp drop' command displays packet drop statistics from the Accelerated Security Path (ASP) on a Cisco ASA. It provides a detailed breakdown of why packets are dropped, including drops due to ACLs, inspection policies, or other security checks. This makes it the correct tool to differentiate between ACL and inspection policy drops.
A security analyst notices that a file that was initially allowed by Cisco AMP for Endpoints has later been determined to be malicious. The analyst needs to investigate the file's propagation across endpoints. Which Cisco AMP feature should the analyst use to view the timeline of events?
Explanation: Device Trajectory in Cisco AMP provides a chronological view of events on an endpoint, showing how a file propagated and what actions were taken. Continuous monitoring and retrospective security allow AMP to re-evaluate files that were initially allowed but later deemed malicious.
+10 more scenario questions available
Practice all Troubleshooting Scenario QuestionsThese questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Troubleshooting Scenario Questions session with instant scoring and detailed explanations.
Start Scenario Practice →