Courseiva

350-701 Practice Question: Secure Network Access, Visibility and Enforcement

Exhibit

Switch# show authentication sessions
Interface: GigabitEthernet0/1
  MAC Address: 0011.2233.4455
  IP Address: 10.1.1.10
  Status: Authz Success
  Domain: DATA
  Oper host mode: single-host
  Oper control dir: both
  Authorized by: Authentication Server
  Vlan Policy: 10
  Session Timeout: N/A
  Idle Timeout: N/A
  Common Session ID: 0A0B0C0D0E0F0000000000001
  Acct Session ID: 0x00000002
  Authc Method: MAB
  Authz Policy: Permit_Access

Refer to the exhibit. A network administrator is troubleshooting a wired client that has successfully authenticated using MAB. However, the client is unable to access resources beyond the local subnet. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The authorization policy is missing a downloadable ACL (dACL) to allow traffic.

The authorization policy 'Permit_Access' likely does not include a downloadable ACL (dACL), which is required on the switch to allow traffic beyond the local subnet. Without a dACL, the switch defaults to denying inter-subnet traffic. Option A is incorrect because the DHCP scope may include a default gateway, but the issue is about traffic filtering, not IP assignment. Option B is incorrect because VLAN 10 assignment is correct; the problem is the lack of a dACL to permit routing. Option C is incorrect because inter-VLAN routing is configured on the router or Layer 3 switch, but the switchport itself needs a dACL to allow traffic from the client.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The client's IP address is from a DHCP scope that does not include a default gateway.

    Why it's wrong here

    This would cause inability to reach any remote network, but the issue is specifically beyond the local subnet.

  • The VLAN policy is incorrect; the client should be in VLAN 20.

    Why it's wrong here

    The VLAN assignment appears successful; a different VLAN would not necessarily prevent inter-subnet access.

  • The switch is not configured for inter-VLAN routing.

    Why it's wrong here

    Inter-VLAN routing is done at the router or Layer 3 switch, not on the access port.

  • The authorization policy is missing a downloadable ACL (dACL) to allow traffic.

    Why this is correct

    Without a dACL, the switch may default to deny all traffic beyond the local subnet.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.