Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: A company has deployed Cisco AnyConnect VPN for…

A company has deployed Cisco AnyConnect VPN for remote access. They want to enforce that only company-managed devices with compliant antivirus and disk encryption can connect. Which solution should be added to the ASA?

⚠ Common exam trap

Cisco often tests the distinction between network security controls (like IPS, DNS filtering, or flow analysis) and endpoint compliance enforcement, leading candidates to confuse a posture assessment requirement with a general security appliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cisco Identity Services Engine (ISE) with posture assessment

Cisco ISE with posture assessment is the correct solution because it integrates with the ASA to enforce endpoint compliance before granting VPN access. Posture assessment checks for specific conditions such as antivirus status, disk encryption, and OS patch levels, ensuring only company-managed devices that meet security policies can connect via AnyConnect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cisco Identity Services Engine (ISE) with posture assessment

    Why this is correct

    ISE performs posture checks to ensure devices meet compliance requirements.

  • Cisco Firepower Threat Defense (FTD) with intrusion policy

    Why it's wrong here

    FTD's intrusion policy does not assess endpoint compliance.

  • Cisco Umbrella with DNS filtering

    Why it's wrong here

    Umbrella provides DNS-layer security, not endpoint posture assessment.

  • Cisco Stealthwatch with NetFlow

    Why it's wrong here

    Stealthwatch provides network visibility and anomaly detection, not endpoint compliance.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.