Courseiva

350-701 Practice Question: Secure Network Access, Visibility and Enforcement

A company is using Cisco ISE for guest access. They have configured a guest portal with a self-registration page. Some guests report that after registering, they are not redirected to the success page but instead see a '401 Unauthorized' error. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The central web authentication (CWA) is not enabled on the switch.

Central web authentication (CWA) must be enabled on the switch to redirect HTTP traffic from unauthenticated guests to the ISE portal. If CWA is not enabled, the switch will not redirect the traffic, resulting in a 401 Unauthorized error after registration. Option A is incorrect because HTTP redirect is configured on the ISE portal itself, not the ISE node, and is not the cause of a 401 error. Option B is incorrect because an untrusted portal certificate would cause a browser security warning, not a 401 error. Option D is incorrect because a missing authorization policy would typically result in an 'Access Denied' message after authentication, not a 401 during the registration redirect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The ISE node is not configured for HTTP redirect.

    Why it's wrong here

    ISE node configuration for HTTP redirect is part of the portal settings; if misconfigured, it would affect redirection but not typically result in 401.

  • The guest portal certificate is not trusted by the client.

    Why it's wrong here

    A certificate issue would cause a security warning, not a 401 error.

  • The central web authentication (CWA) is not enabled on the switch.

    Why this is correct

    Without CWA, the switch does not redirect HTTP traffic to ISE, causing a 401 unauthorized error.

  • The authorization policy for guests is missing.

    Why it's wrong here

    Missing authorization policy would likely result in 'Access Denied' after successful registration.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.