Courseiva
hardMultiple ChoiceObjective-mapped

350-701 Practice Question: A network administrator is configuring Cisco ISE…

A network administrator is configuring Cisco ISE for posture assessment. A Windows laptop connects to the network and passes 802.1X authentication. ISE then checks if the antivirus software is running and if the OS patches are up to date. If the posture check fails, ISE should dynamically restrict the endpoint to a remediation VLAN. Which mechanism allows ISE to change the VLAN assignment after authentication without requiring the user to reauthenticate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change of Authorization (CoA)

Change of Authorization (CoA) allows ISE to dynamically change the authorization state (e.g., VLAN or ACL) on the network device after the initial authentication. This is used to enforce posture policies without requiring the endpoint to reauthenticate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Change of Authorization (CoA)

    Why this is correct

    CoA enables dynamic change of authorization attributes like VLAN or ACL after authentication.

  • 802.1X reauthentication

    Why it's wrong here

    Reauthentication re-initiates the 802.1X process, which is slower and not as dynamic as CoA.

  • MAB reauthentication

    Why it's wrong here

    MAB reauthentication is not used for dynamic VLAN changes; CoA is the correct mechanism.

  • RADIUS Disconnect

    Why it's wrong here

    RADIUS Disconnect tears down the session but does not reassign VLAN; CoA is used for dynamic changes.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.