VLAN misconfiguration is one of the top sources of connectivity failures in real networks and one of the most tested areas on the CCNA. These questions cover VLAN access ports, 802.1Q trunks, native VLANs, and router-on-a-stick or layer-3 switch inter-VLAN routing.
Start Scenario PracticeA network engineer is troubleshooting an 802.1X deployment where some Windows 10 endpoints fail to authenticate. Logs show that the client sends an EAPoL-Start but never receives an EAP-Request/Identity. The switch port configuration is: interface GigabitEthernet0/1 switchport mode access authentication port-control auto dot1x pae authenticator Which additional command is most likely needed?
Explanation: The command dot1x system-auth-control is a global configuration command that enables 802.1X authentication on the switch. Without it, the per-interface dot1x pae authenticator and authentication port-control auto commands have no effect because the 802.1X process is not globally enabled. This is why the client sends EAPoL-Start but the switch never responds with EAP-Request/Identity.
Cisco ISE is configured with posture assessment to ensure endpoints meet security requirements before gaining network access. After a posture check, ISE needs to dynamically change the VLAN assignment for a non-compliant endpoint. Which ISE feature enables this real-time change?
Explanation: Change of Authorization (CoA) allows ISE to dynamically update authentication and authorization attributes such as VLAN assignment.
In a Cisco ISE deployment, after a device passes posture assessment, ISE needs to dynamically change the VLAN assignment for the device. Which protocol or feature enables ISE to send a new authorization policy to the network access device without requiring the endpoint to reauthenticate?
Explanation: Change of Authorization (CoA) allows ISE to send real-time authorization changes (e.g., VLAN change) to the NAD using RADIUS Disconnect or Change of Authorization messages, without requiring the client to reauthenticate.
An organization uses Cisco ISE to enforce posture compliance. After a user's machine is patched, ISE sends a command to the switch to reclassify the endpoint from a restricted VLAN to a full-access VLAN. Which ISE feature accomplishes this?
Explanation: Change of Authorization (CoA) allows ISE to dynamically change an authenticated session's attributes, such as VLAN assignment or ACL, without requiring reauthentication.
A network administrator is configuring Cisco ISE for posture assessment. A Windows laptop connects to the network and passes 802.1X authentication. ISE then checks if the antivirus software is running and if the OS patches are up to date. If the posture check fails, ISE should dynamically restrict the endpoint to a remediation VLAN. Which mechanism allows ISE to change the VLAN assignment after authentication without requiring the user to reauthenticate?
Explanation: Change of Authorization (CoA) allows ISE to dynamically change the authorization state (e.g., VLAN or ACL) on the network device after the initial authentication. This is used to enforce posture policies without requiring the endpoint to reauthenticate.
+2 more scenario questions available
Practice all VLAN and Inter-VLAN Routing ScenariosVLAN misconfiguration is one of the top sources of connectivity failures in real networks and one of the most tested areas on the CCNA. These questions cover VLAN access ports, 802.1Q trunks, native VLANs, and router-on-a-stick or layer-3 switch inter-VLAN routing. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full VLAN and Inter-VLAN Routing Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →