CCNP Security Practice Question
A network engineer needs to provide secure remote-access VPN connectivity for employees using Cisco AnyConnect. The requirement is to use digital certificates issued by the corporate PKI for both server and client authentication. Which component must be configured on the Cisco ASA to validate client certificates presented during the VPN session?
⚠ Common exam trap
The trap here is assuming any authentication configuration, such as a local user or LDAP map, will validate certificates, when only a trustpoint containing the issuing CA certificate enables certificate chain validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A trustpoint containing the CA certificate that signed the client certificates.
Certificate-based client authentication requires the ASA to trust the CA that issued the client certificates. Configuring a trustpoint with the CA certificate allows the ASA to validate the chain presented by AnyConnect. Pre-shared keys, local user accounts, and LDAP attribute maps do not perform certificate validation and therefore cannot fulfill the PKI-based authentication requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A trustpoint containing the CA certificate that signed the client certificates.
Why this is correct
To validate client certificates, the ASA must trust the issuing CA. A trustpoint holds the CA certificate and enables the ASA to verify the certificate chain presented by AnyConnect clients. Without this trustpoint, the ASA cannot confirm the client certificate is genuine, so it is the required configuration for certificate-based client authentication.
- ✗
A local user account with the privilege level 15 assigned.
Why it's wrong here
A local user account authenticates a username and password, not a client certificate. Assigning privilege level 15 relates to administrative access, not VPN client authentication. It does not validate certificates and does not meet the certificate-based authentication requirement described in the scenario.
- ✗
An IKEv2 pre-shared key configured under the tunnel group.
Why it's wrong here
A pre-shared key is used for IKEv2 peer authentication in site-to-site or remote-access tunnels that rely on PSK instead of certificates. The scenario explicitly requires digital certificates for client authentication, so a PSK would contradict the design and would not validate client certificates. It is the wrong authentication method here.
- ✗
An LDAP attribute map for group policy assignment.
Why it's wrong here
An LDAP attribute map maps directory attributes to ASA group policies for authorization, not authentication. It does not validate client certificates. While useful for assigning policies based on directory data, it plays no role in verifying the certificate chain presented by AnyConnect clients, so it does not satisfy the requirement.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.