Courseiva
Network SecuritymediumMultiple ChoiceObjective-mapped

350-701 Network Security Practice Question

A company uses Cisco AnyConnect for remote access VPN. They want to allow only specific Active Directory groups to access the corporate network. Which feature on the ASA or FTD should be configured to enforce this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Dynamic Access Policy (DAP)

Dynamic Access Policies (DAP) can evaluate user attributes from AD to assign access rights.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Connection profile with LDAP attribute map

    Why it's wrong here

    Connection profiles map users to group policies, but DAP provides dynamic control.

  • AAA server group

    Why it's wrong here

    AAA server group defines authentication servers but not per-group access.

  • Group Policy with filter on group membership

    Why it's wrong here

    Group policies do not natively filter AD groups; DAP is used.

  • Dynamic Access Policy (DAP)

    Why this is correct

    DAP allows granular access based on user attributes like AD group membership.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.