hardMultiple ChoiceObjective-mapped
350-701 Practice Question: A network administrator is configuring Cisco ISE…
A network administrator is configuring Cisco ISE for posture assessment. A Windows laptop connects to the network and passes 802.1X authentication. ISE then checks if the antivirus software is running and if the OS patches are up to date. If the posture check fails, ISE should dynamically restrict the endpoint to a remediation VLAN. Which mechanism allows ISE to change the VLAN assignment after authentication without requiring the user to reauthenticate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change of Authorization (CoA)
Change of Authorization (CoA) allows ISE to dynamically change the authorization state (e.g., VLAN or ACL) on the network device after the initial authentication. This is used to enforce posture policies without requiring the endpoint to reauthenticate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change of Authorization (CoA)
Why this is correct
CoA enables dynamic change of authorization attributes like VLAN or ACL after authentication.
- ✗
802.1X reauthentication
Why it's wrong here
Reauthentication re-initiates the 802.1X process, which is slower and not as dynamic as CoA.
- ✗
MAB reauthentication
Why it's wrong here
MAB reauthentication is not used for dynamic VLAN changes; CoA is the correct mechanism.
- ✗
RADIUS Disconnect
Why it's wrong here
RADIUS Disconnect tears down the session but does not reassign VLAN; CoA is used for dynamic changes.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.