350-701 Practice Question: Secure Network Access, Visibility and Enforcement
A large enterprise uses Cisco ISE with pxGrid to share context with Firepower for threat containment. When a Firepower detects an infected endpoint, it triggers a pxGrid quarantine action that changes the endpoint's authorization profile. The engineer observes that the quarantine is applied, but after the Firepower clears the threat, the endpoint does not regain its original access. What is the most likely reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ISE session is not forced to reauthenticate after quarantine release
When Firepower clears a threat and sends a clearance message to ISE via pxGrid, ISE may update the endpoint's authorization policy but does not automatically force the existing session to reauthenticate. The endpoint remains in the quarantine state because the network access device (NAD) still has the old session attributes. To restore original access, a Change of Authorization (CoA) must be sent to the NAD to trigger reauthentication. Option B correctly identifies that the session is not forced to reauthenticate after quarantine release. Option A is incorrect because Firepower does send the clearance message. Option C is incorrect because the NAD accepted the quarantine CoA, indicating CoA support. Option D is incorrect because the authorization policy order is not the issue; the problem is the lack of reauthentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firepower failed to send the clearance message to ISE
Why it's wrong here
Firepower does send a clearance message to ISE after the threat is cleared, so this is not the reason.
- ✓
The ISE session is not forced to reauthenticate after quarantine release
Why this is correct
Correct. The quarantine action changes the authorization profile, but after clearance, the session is not forced to reauthenticate, so the endpoint remains in quarantine.
- ✗
The network access device does not support CoA
Why it's wrong here
The network access device (NAD) already supported CoA to apply the quarantine, so it likely supports CoA for release as well. The issue is that CoA for reauthentication is not triggered.
- ✗
ISE authorization policy is not ordered correctly
Why it's wrong here
The authorization policy order may affect which profile is applied, but the core problem is that the session is not reauthenticated after quarantine release.
Go deeper
Related to this question
About these practice questions
One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.