350-701 Practice Question: Secure Network Access, Visibility and Enforcement
Exhibit
Switch# show authentication sessions Interface: GigabitEthernet0/1 MAC Address: 0011.2233.4455 IP Address: 10.1.1.10 Status: Authz Success Domain: DATA Oper host mode: single-host Oper control dir: both Authorized by: Authentication Server Vlan Policy: 10 Session Timeout: N/A Idle Timeout: N/A Common Session ID: 0A0B0C0D0E0F0000000000001 Acct Session ID: 0x00000002 Authc Method: MAB Authz Policy: Permit_Access
Refer to the exhibit. A network administrator is troubleshooting a wired client that has successfully authenticated using MAB. However, the client is unable to access resources beyond the local subnet. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authorization policy is missing a downloadable ACL (dACL) to allow traffic.
The authorization policy 'Permit_Access' likely does not include a downloadable ACL (dACL), which is required on the switch to allow traffic beyond the local subnet. Without a dACL, the switch defaults to denying inter-subnet traffic. Option A is incorrect because the DHCP scope may include a default gateway, but the issue is about traffic filtering, not IP assignment. Option B is incorrect because VLAN 10 assignment is correct; the problem is the lack of a dACL to permit routing. Option C is incorrect because inter-VLAN routing is configured on the router or Layer 3 switch, but the switchport itself needs a dACL to allow traffic from the client.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The client's IP address is from a DHCP scope that does not include a default gateway.
Why it's wrong here
This would cause inability to reach any remote network, but the issue is specifically beyond the local subnet.
- ✗
The VLAN policy is incorrect; the client should be in VLAN 20.
Why it's wrong here
The VLAN assignment appears successful; a different VLAN would not necessarily prevent inter-subnet access.
- ✗
The switch is not configured for inter-VLAN routing.
Why it's wrong here
Inter-VLAN routing is done at the router or Layer 3 switch, not on the access port.
- ✓
The authorization policy is missing a downloadable ACL (dACL) to allow traffic.
Why this is correct
Without a dACL, the switch may default to deny all traffic beyond the local subnet.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.