Courseiva

Deploying Cisco ISE for Network Access Control with Identity and Posture

A security architect is designing network access control for a campus network. The requirement is to authenticate users before granting network access and to enforce policies based on user identity and device posture. Which solution should be deployed?

Quick Answer

The answer is Cisco Identity Services Engine (ISE). This is the correct choice because ISE is purpose-built for network access control with identity and posture, combining 802.1X, MAB, and web authentication to verify users, then enforcing policies through dynamic VLAN assignment, downloadable ACLs, or Security Group Tags based on both who the user is and whether their device meets posture requirements like antivirus status or OS patch levels. On the Cisco SCOR 350-701 exam, this question tests your ability to distinguish ISE from a generic AAA server such as Cisco ACS or a standalone RADIUS solution—a common trap is assuming any AAA platform suffices, but only ISE integrates posture assessment via AnyConnect or the NAC Agent, along with profiling, guest access, and BYOD onboarding. A helpful memory tip: think of ISE as the “identity plus state enforcer”—it cares not just who you are, but what condition your device is in.

⚠ Common exam trap

Cisco often tests the distinction between AAA for device administration (TACACS+) and AAA for network access (RADIUS/ISE), leading candidates to mistakenly choose a generic AAA server when the question specifically requires identity- and posture-based enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cisco Identity Services Engine (ISE)

Cisco ISE is the correct solution because it provides centralized policy-based network access control that authenticates users via 802.1X, MAB, or web authentication, and enforces dynamic VLAN assignment, ACLs, or SGTs based on user identity and device posture (e.g., compliance with antivirus, OS patches). Unlike a generic AAA server, ISE integrates with posture assessment (via AnyConnect or NAC Agent) and supports profiling, guest access, and BYOD onboarding, directly meeting the requirement for identity- and posture-based enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AAA server with TACACS+

    Why it's wrong here

    TACACS+ is for device administration, not network access control with posture.

  • VPN concentrator with client certificate authentication

    Why it's wrong here

    VPN is for remote access, not campus network access control.

  • Next-generation firewall with application control

    Why it's wrong here

    Firewalls do not perform user authentication and posture assessment for network access.

  • Cisco Identity Services Engine (ISE)

    Why this is correct

    ISE provides centralized policy enforcement for network access with user and device context.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network administrator wants to centrally manage and enforce access policies for wired and wireless users. Which Cisco product provides this functionality?

easy
  • A.Cisco Identity Services Engine (ISE)
  • B.Cisco Prime Infrastructure
  • C.Cisco Adaptive Security Appliance (ASA)
  • D.Cisco Wireless LAN Controller (WLC)

Why A: Cisco Identity Services Engine (ISE) is the correct answer because it provides centralized policy management for both wired and wireless users through a unified, context-aware platform. ISE uses 802.1X, MAC Authentication Bypass (MAB), and posture assessment to enforce access policies based on user identity, device type, and location, integrating with network devices via RADIUS (RFC 2865) and TACACS+ for authentication, authorization, and accounting (AAA).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.