Courseiva
hardMultiple ChoiceObjective-mapped

350-701 Practice Question: An enterprise migrated its e-commerce application…

An enterprise migrated its e-commerce application to AWS. They use Cisco Secure Workload (Tetration) for microsegmentation. After enabling enforcement, legitimate traffic between the web tier and database tier is being blocked. The security team verified that the policy allows the traffic based on labels. The Tetration console shows the enforcement mode as 'active blocking'. The database server is in a different VPC, and the web server is in a public subnet. The agents are running on both workloads and report correctly. Which configuration step is most likely missing?

⚠ Common exam trap

Cisco often tests the misconception that agents alone are sufficient for policy enforcement across VPCs, when in fact the cloud connector is required to bridge the cloud infrastructure metadata gap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The cloud connector (e.g., AWS cloud connector) is not configured

Cisco Secure Workload (Tetration) relies on cloud connectors to synchronize cloud infrastructure metadata (e.g., VPCs, subnets, instances) and enforce microsegmentation policies across VPC boundaries. Without a configured AWS cloud connector, Tetration cannot discover or enforce policies on resources in a different VPC, even if agents are running and labels are correctly assigned. The 'active blocking' enforcement mode indicates the policy is being applied, but the missing connector prevents the policy from being properly mapped to the database server in the separate VPC, causing legitimate traffic to be blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The cloud connector (e.g., AWS cloud connector) is not configured

    Why this is correct

    Cloud connector provides metadata that allows Tetration to understand cloud networking and apply policies correctly across VPCs.

  • The enforcement scope does not include the VPC peering connection

    Why it's wrong here

    Enforcement scopes are per-workload; VPC peering is not a scope parameter.

  • The application dependency mapping needs to be refreshed

    Why it's wrong here

    Dependency mapping is automatic and refreshes periodically; not the cause of blocking.

  • The agents on the database server are not running

    Why it's wrong here

    The scenario states agents are running and reporting correctly.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.