350-701 Practice Question: Secure Network Access, Visibility and Enforcement
An organization is using Cisco ISE to enforce posture compliance. Endpoints that are non-compliant should be placed into a quarantine VLAN. Which ISE policy component is used to assign the VLAN?
⚠ Common exam trap
Many exam-takers confuse the role of the Authorization Profile with the Policy Set or Authentication Policy, mistakenly thinking that VLAN assignment is part of the authentication decision rather than a separate authorization action applied after successful authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization profile
An Authorization Profile in Cisco ISE defines the enforcement actions to be applied to an endpoint after successful authentication and authorization. When a posture assessment determines an endpoint is non-compliant, the authorization policy can match that condition and return an authorization profile that includes a specific VLAN ID (e.g., quarantine VLAN) via RADIUS attributes such as Tunnel-Private-Group-ID (RFC 2868). This VLAN assignment is a core function of the authorization profile, not of authentication or profiling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization profile
Why this is correct
Authorization profile contains attributes like VLAN ID, dACL, etc.
- ✗
Policy set
Why it's wrong here
Policy set is a grouping of authentication and authorization policies.
- ✗
Profiling policy
Why it's wrong here
Profiling policy identifies device type, not access rights.
- ✗
Authentication policy
Why it's wrong here
Authentication policy does not define VLAN assignment.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.