mediumMultiple ChoiceObjective-mapped
350-701 Practice Question: A security analyst needs to enforce that all…
A security analyst needs to enforce that all endpoints have antivirus software running and are up-to-date with patches before granting full network access. Which Cisco ISE feature should be used to enforce this policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Posture assessment
Posture assessment checks endpoints for compliance with security policies (e.g., antivirus status, patch level) before granting access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change of Authorization (CoA)
Why it's wrong here
CoA dynamically changes authorization but does not perform the compliance check itself.
- ✗
Profiling
Why it's wrong here
Profiling identifies device type, not compliance status.
- ✓
Posture assessment
Why this is correct
Posture assessment evaluates endpoint security posture and can restrict access until compliance is met.
- ✗
TrustSec SGT assignment
Why it's wrong here
TrustSec assigns Security Group Tags for segmentation, not for compliance checks.
Go deeper
Related to this question
About these practice questions
This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.