Courseiva

350-701 Practice Question: Secure Network Access, Visibility and Enforcement

A company has deployed Cisco ISE for network access control. After a recent upgrade, the operations team notices that some users are being assigned incorrect authorization profiles. The ISE logs show that the users are being matched to the correct identity group, but the authorization result is different from expected. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the concept that authorization policies are evaluated in order of precedence, and candidates mistakenly focus on authentication or group assignment when the real issue is rule ordering in the authorization policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The authorization policy rules are not in the correct order, causing a different rule to match first.

In Cisco ISE, authorization policies are evaluated in top-down order, and the first matching rule is applied. Even if users are correctly assigned to an identity group, a higher-priority authorization policy rule that matches on other conditions (e.g., endpoint profile, device type, or time condition) can override the expected result. This is the most likely cause when authentication and group assignment are correct but the authorization result is unexpected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The passive identity feature is overriding the user's group assignment.

    Why it's wrong here

    Passive identity does not override group assignment.

  • The authorization policy rules are not in the correct order, causing a different rule to match first.

    Why this is correct

    ISE uses first-match logic for authorization policies.

  • The network device group assignment has changed, causing the device to be in a different group.

    Why it's wrong here

    Network device groups affect which policies apply, but not the matching order.

  • The authentication policy is misconfigured, causing users to be placed in the wrong identity group.

    Why it's wrong here

    The logs show users are in the correct identity group.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.