easyMultiple ChoiceObjective-mapped
350-701 Practice Question: A company with 500 employees uses Cisco Web…
A company with 500 employees uses Cisco Web Security Appliance (WSA) as a proxy. They have a policy to block access to social media sites during working hours (9 AM - 5 PM) for all users except the marketing team. The marketing team must have unrestricted access at all times. The WSA is configured with a time-based access policy that blocks the 'Social Networking' category from 9 AM to 5 PM, and an identity policy that identifies the marketing team by Active Directory group. However, marketing users report that they are blocked from social media during working hours. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently confuse identity policies with access policies, thinking that identifying a user group automatically grants them different access, when in fact the identity policy must be paired with a separate access policy that explicitly overrides the global policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The identity policy for the marketing team has a 'Use Global Policy' action for social networking, which then applies the time-based block.
When an identity policy is set to 'Use Global Policy' for a specific category, it defers to the global access policy, which in this case includes the time-based block for social networking. Since the marketing team's identity policy does not explicitly override the global policy with an 'Allow' or 'Monitor' action for the 'Social Networking' category, the time-based block applies to them as well.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The time-based policy is set to block social media from 9 AM to 5 PM, but the marketing team's identity policy is not explicitly set to 'Monitor' or 'Allow' for that category.
Why it's wrong here
The identity policy should override the time-based policy if set correctly.
- ✗
The WSA requires authentication for all users, but marketing users are not prompted to authenticate.
Why it's wrong here
If marketing users are not authenticated, they would fall under a default policy, but the scenario implies they are identified.
- ✓
The identity policy for the marketing team has a 'Use Global Policy' action for social networking, which then applies the time-based block.
Why this is correct
If the identity policy uses 'Use Global Policy', the time-based block from the global policy applies, blocking marketing users.
- ✗
The marketing team's Active Directory group is not being recognized by the WSA due to a synchronization issue.
Why it's wrong here
Synchronization issues would affect all policies, not just social media, and marketing likely has other access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.