Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: A company with 500 employees uses Cisco Web…

A company with 500 employees uses Cisco Web Security Appliance (WSA) as a proxy. They have a policy to block access to social media sites during working hours (9 AM - 5 PM) for all users except the marketing team. The marketing team must have unrestricted access at all times. The WSA is configured with a time-based access policy that blocks the 'Social Networking' category from 9 AM to 5 PM, and an identity policy that identifies the marketing team by Active Directory group. However, marketing users report that they are blocked from social media during working hours. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently confuse identity policies with access policies, thinking that identifying a user group automatically grants them different access, when in fact the identity policy must be paired with a separate access policy that explicitly overrides the global policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The identity policy for the marketing team has a 'Use Global Policy' action for social networking, which then applies the time-based block.

When an identity policy is set to 'Use Global Policy' for a specific category, it defers to the global access policy, which in this case includes the time-based block for social networking. Since the marketing team's identity policy does not explicitly override the global policy with an 'Allow' or 'Monitor' action for the 'Social Networking' category, the time-based block applies to them as well.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The time-based policy is set to block social media from 9 AM to 5 PM, but the marketing team's identity policy is not explicitly set to 'Monitor' or 'Allow' for that category.

    Why it's wrong here

    The identity policy should override the time-based policy if set correctly.

  • The WSA requires authentication for all users, but marketing users are not prompted to authenticate.

    Why it's wrong here

    If marketing users are not authenticated, they would fall under a default policy, but the scenario implies they are identified.

  • The identity policy for the marketing team has a 'Use Global Policy' action for social networking, which then applies the time-based block.

    Why this is correct

    If the identity policy uses 'Use Global Policy', the time-based block from the global policy applies, blocking marketing users.

  • The marketing team's Active Directory group is not being recognized by the WSA due to a synchronization issue.

    Why it's wrong here

    Synchronization issues would affect all policies, not just social media, and marketing likely has other access.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.