Practise command-choice questions where the task is to identify the correct verification, configuration or troubleshooting command.
Start Scenario PracticeA network administrator configures Cisco ISE to identify devices by analyzing DHCP requests, HTTP user agents, and SNMP queries. Which ISE feature is being used?
Explanation: Profiling in ISE uses probes (DHCP, HTTP, SNMP, etc.) to identify device type and attributes.
An administrator is troubleshooting authentication failures for VPN users. The RADIUS server is reachable via ping, but users receive 'AAA authentication failed'. Which command should be used to test communication with the RADIUS server?
Explanation: The 'test aaa group radius user password' command is specifically designed to simulate an authentication attempt against a RADIUS server, allowing the administrator to verify whether the RADIUS server is properly processing credentials. Since the RADIUS server is reachable via ping but users still fail, this command isolates whether the issue lies in the AAA authentication process itself, such as incorrect shared secret, user credentials, or RADIUS attribute mismatches.
A cloud security team is investigating a possible data exfiltration incident involving an AWS S3 bucket configured with cross-region replication. Which Cisco Cloudlock feature can detect unusual replication patterns that may indicate data theft?
Explanation: Cloudlock UEBA is the correct answer because it establishes behavioral baselines for user and entity activities, such as S3 bucket replication patterns. When cross-region replication deviates from the learned baseline—e.g., unusual volume, frequency, or destination—UEBA generates an anomaly alert, directly detecting potential data exfiltration. This is a core capability of Cisco Cloudlock's cloud access security broker (CASB) functionality.
Refer to the exhibit. A network administrator configured IP Source Guard and DHCP Snooping on a switch. A host connected to GigabitEthernet0/2 with MAC address 0050.7966.6801 has been assigned IP 192.168.1.10 via DHCP. The host now tries to use IP 192.168.1.20. What will happen?
Explanation: IP Source Guard uses DHCP snooping binding table to enforce IP-to-port mapping. When the host at GigabitEthernet0/2 with MAC 0050.7966.6801 attempts to use IP 192.168.1.20 instead of its DHCP-assigned IP 192.168.1.10, the switch compares the source IP of the packet against the binding table. Since 192.168.1.20 is not bound to that port and MAC, the switch drops all traffic from that host with source IP 192.168.1.20, preventing IP spoofing.
A network engineer is troubleshooting an 802.1X deployment where some Windows 10 endpoints fail to authenticate. Logs show that the client sends an EAPoL-Start but never receives an EAP-Request/Identity. The switch port configuration is: interface GigabitEthernet0/1 switchport mode access authentication port-control auto dot1x pae authenticator Which additional command is most likely needed?
Explanation: The command dot1x system-auth-control is a global configuration command that enables 802.1X authentication on the switch. Without it, the per-interface dot1x pae authenticator and authentication port-control auto commands have no effect because the 802.1X process is not globally enabled. This is why the client sends EAPoL-Start but the switch never responds with EAP-Request/Identity.
+10 more scenario questions available
Practice all Which Command Should the Administrator Use Practice QuestionsPractise command-choice questions where the task is to identify the correct verification, configuration or troubleshooting command. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Which Command Should the Administrator Use Practice Questions session with instant scoring and detailed explanations.
Start Scenario Practice →