Courseiva

CCNA Web Auth And Guest Services Questions

41 questions · Web Auth And Guest Services topic · All types, answers revealed

1
MCQhard

In a CWA scenario, the user is redirected to the portal, authenticates, but the session is not transitioning from the 'redirected' state to the 'authenticated' state. What is the most likely cause?

A.The NAD is missing the 'aaa server radius dynamic-author' configuration.
B.The Guest user group is missing from the Policy Set.
C.The Redirect ACL is applied to the wrong interface.
D.The portal URL is incorrect.
AnswerA

CoA requires this configuration on the switch to listen for ISE's re-authentication request.

Why this answer

After successful portal authentication, ISE sends a RADIUS CoA to the NAD. If the NAD is not configured to accept CoA, the session remains in the initial state.

2
MCQhard

You are implementing a Guest flow that requires the user to accept an Acceptable Use Policy (AUP). Where is the AUP text configured within the Cisco ISE portal settings?

A.Policy > Policy Elements > Results > Authorization Profiles
B.Work Centers > Guest Access > Settings > AUP
C.Guest Access > Configure > Guest Portals > [Portal Name] > Portal Page Customization
D.Administration > System > Settings > Guest
AnswerC

This is the correct path for customizing portal pages.

Why this answer

The AUP is defined within the Guest Portal's 'Page Customization' settings under the 'Acceptable Use Policy' section.

3
Multi-Selectmedium

Which THREE of the following are required components to successfully implement Central Web Authentication (CWA) with a Cisco WLC?

Select 3 answers
A.A static IP address assigned to all guest clients.
B.A URL Redirect ACL defined on the WLC.
C.An Authorization Profile with 'Web Redirection' enabled.
D.An ISE Authorization Policy rule that returns the redirection profile.
E.A redirection policy in the WLC's WLAN configuration.
AnswersB, C, D

The WLC uses this ACL to determine which traffic should be redirected to ISE.

Why this answer

CWA requires a specific authorization profile that includes redirection, an authentication rule that bypasses MAB or uses it as a trigger, and the appropriate URL redirect ACLs.

4
MCQmedium

A guest user reports they receive a certificate warning when redirected to the ISE Guest portal. What is the most common cause of this issue?

A.The ISE portal is configured for HTTP instead of HTTPS.
B.The DNS server is not resolving the ISE FQDN.
C.The ISE server certificate is self-signed or not trusted by the client device.
D.The switch is not configured for SSL interception.
AnswerC

Browsers require trusted certificates for secure connections.

Why this answer

Guest portals use HTTPS. If the ISE certificate is not signed by a trusted CA, the browser will display a warning.

5
MCQmedium

You are troubleshooting a Guest flow where the client hits the portal but cannot authenticate. You notice the MAC address is not being cached properly. Which setting in the Guest Portal configuration is responsible for enabling MAC caching?

A.Enable Auto-Login
B.Enable Guest Flow Bypass
C.Enable MAC Caching
D.Enable Device Registration
AnswerC

This is the specific setting to enable the feature.

Why this answer

MAC Caching allows ISE to remember the device after the first authentication, preventing repeated portal logins. This is enabled under the Guest Portal settings for MAC Caching.

6
MCQmedium

A network administrator needs to implement self-registered guest access where the guest must provide an email address for validation. Which feature in the Guest Portal settings allows for this?

A.Registration Form settings.
B.Authentication Policy rules.
C.Guest Type settings.
D.Device Registration settings.
E.Sponsor Group settings.
AnswerA

Within the Registration Form settings of the Guest Portal, you can enable specific fields and define the validation requirements.

Why this answer

The 'Self-Registration' page settings in the Guest Portal configuration allow enabling fields such as 'Email Address' and configuring the 'Email Validation' mechanism.

7
Multi-Selecthard

Which THREE of the following are steps involved in the guest portal sponsor approval process?

Select 3 answers
A.The sponsor logs into the sponsor portal to review and approve the request.
B.The guest registers for an account on the self-registration portal.
C.The ISE automatically approves the account after 10 minutes.
D.The sponsor receives an automated email notification about the pending account.
E.The guest must physically visit the sponsor's office.
AnswersA, B, D

This is the action step.

Why this answer

The workflow involves the guest requesting access, the sponsor receiving an email notification, and the sponsor logging into the portal to approve or deny the request.

8
MCQmedium

If you want a guest user to be automatically redirected to a specific webpage (e.g., company news) after a successful login, where is this configured?

A.In the Authorization Profile.
B.In the Guest Type configuration.
C.In the Redirect ACL on the NAD.
D.In the Guest Portal Settings under 'Post-Login' page.
AnswerD

This is the correct setting for post-login redirection.

Why this answer

The 'Post-Login' landing page configuration in the Guest Portal allows you to define the URL to which the user is redirected after a successful authentication.

9
MCQmedium

Which guest portal type should you select if you want to allow users to connect to the network without any authentication, simply by clicking an 'Accept' button?

A.Sponsored Guest Portal
B.Guest Portal
C.Self-Registered Guest Portal
D.Hotspot Portal
AnswerD

Hotspot provides simple click-through access.

Why this answer

The Hotspot portal is specifically designed for 'click-through' access, commonly used in public Wi-Fi environments.

10
MCQhard

A user is authenticating via the Sponsored Guest portal. After the sponsor approves the guest, the user still cannot access the network. What is the most common reason for this if the RADIUS flow is correct?

A.The NAD is not processing the CoA request sent by ISE.
B.The guest password has expired.
C.The guest account is not in the correct group.
D.The browser cache is preventing the redirect.
AnswerA

The CoA is necessary to change the authorization state from 'pending' to 'authorized'.

Why this answer

If the session is not updated, the switch doesn't know the status has changed. A CoA is required to re-evaluate the session after approval.

11
MCQeasy

Which portal is intended for guest users to manage their own registered devices, such as adding or removing their personal laptops?

A.My Devices Portal
B.Hotspot Portal
C.Sponsor Portal
D.Guest Portal
AnswerA

This is the correct portal for device management.

Why this answer

The 'My Devices' portal is explicitly designed for guests or employees to manage their own registered devices for network access.

12
Multi-Selecthard

Which THREE of the following are valid actions an administrator can take in the Sponsor Portal?

Select 3 answers
A.Change the global ISE logging level.
B.Create a new guest account.
C.Modify the existing portal theme.
D.Delete an existing guest account.
E.Extend the expiration time of a guest account.
AnswersB, D, E

Core sponsor capability.

Why this answer

The Sponsor Portal provides tools for account creation, lifecycle management (extending/revoking), and viewing the status of guest accounts.

13
MCQmedium

You want to customize the guest portal so that it displays the company logo and specific terms of use. Where is this configuration performed within the Cisco ISE GUI?

A.Administration > System > Settings > Portal Configuration
B.Policy > Policy Elements > Results > Authorization > Authorization Profiles
C.Work Centers > Guest Access > Portals & Components
D.Operations > Troubleshoot > Diagnostic Tools
AnswerC

This is the correct location to edit the Guest Portal and its associated customization settings.

Why this answer

Portal customization is managed under the Guest Access menu, specifically within the Portal Builder of the selected portal type.

14
MCQhard

If a user is redirected to the Guest portal but receives a '404 Page Not Found' error, what is the most likely configuration issue?

A.The NAD is blocking the traffic.
B.The Guest Portal is not enabled on the PSN.
C.The redirect URL is pointing to a non-existent portal path or the PSN is not reachable.
D.The user's account is expired.
AnswerC

This causes the 404 error.

Why this answer

If the portal FQDN is not resolvable or the portal service on the PSN is not active, the user will reach a non-existent page.

15
Multi-Selectmedium

Which TWO of the following are common reasons for a Guest portal to display an 'Internal Server Error'?

Select 2 answers
A.The guest's device is blocked by a MAC filter.
B.The Guest user provided an invalid password.
C.The NAD is not configured for RADIUS.
D.The portal service on the PSN is unresponsive.
E.The ISE database is unreachable.
AnswersD, E

Common node-specific issue.

Why this answer

Internal Server Errors often relate to issues with the ISE node itself, such as database connectivity problems or the portal service being crashed/unresponsive.

16
MCQeasy

Which type of guest account is best suited for a visitor who needs access for exactly one business day and should have their account automatically deleted thereafter?

A.Self-Registered Guest
B.Hotspot Guest
C.Sponsored Guest
D.Daily Guest Account
AnswerD

This provides the specific time-bound access requested.

Why this answer

An 'Expiring' account is designed to be time-bound, and ISE automatically removes it upon expiration based on the defined policies.

17
MCQeasy

What is the purpose of the 'Guest Type' configuration in Cisco ISE?

A.To define the graphical user interface layout of the guest portal.
B.To assign a specific sponsor to a guest.
C.To set the IP address pool for the guest VLAN.
D.To define the attributes of the guest account such as duration and permissions.
AnswerD

Guest Types allow you to set policies for how long an account lasts and what access the guest is granted.

Why this answer

Guest types define the lifecycle of a guest account, including time-to-live, max devices, and session duration.

18
MCQmedium

When setting up a self-registration portal, you want to require that the guest's email address is validated before granting access. Which feature should you enable?

A.Enable Guest MAC Caching
B.Self-Registration Account Activation
C.Enable Captcha
D.Require Sponsor Approval
AnswerB

This setting enables the email verification workflow.

Why this answer

Email verification requires the user to click a link sent to their email to activate the account. This is configured in the self-registration portal settings.

19
MCQmedium

You are configuring Central Web Authentication (CWA) and need to ensure the client is redirected to the Cisco ISE portal. Which authorization profile configuration is mandatory to achieve this redirection?

A.Set the Access Type to Permit Access and enable URL Redirect with the portal ID.
B.Enable 'Authentication Bypass' in the authorization profile to allow the traffic to hit the redirect rule.
C.Configure the profile as a standard permit access profile with a dynamic VLAN assignment.
D.Set the Access Type to Web Auth and manually input the redirect IP address in the Custom Attributes field.
AnswerA

The Web Redirection settings must be configured to point to the specific portal, which triggers the WLC to send a redirect URL to the client.

Why this answer

For CWA, the authorization profile must include a dACL or a filter-ID, and the Web Redirection component must be enabled with the specific Client Provisioning or Guest portal selected as the target.

20
MCQeasy

Where do you customize the visual look and feel of the guest portal, such as logos and background colors?

A.Administration > System > Settings
B.Work Centers > Guest Access > Configure > Guest Portals
C.Policy > Policy Elements > Results
D.Administration > Identity Management > Identities
AnswerB

This is the correct location to edit portal appearance.

Why this answer

The 'Portal Page Customization' section within the specific portal configuration allows for uploading custom logos and changing themes.

21
MCQhard

When using Local Web Authentication (LWA) on a WLC, which entity performs the actual credentials check against Cisco ISE?

A.The Wireless LAN Controller (WLC).
B.The Access Point (AP) in FlexConnect mode.
C.The Cisco ISE node directly.
D.The client browser via HTTPS POST.
AnswerA

The WLC collects the username/password and forwards them to Cisco ISE via a RADIUS Access-Request.

Why this answer

In LWA, the WLC acts as the RADIUS client that sends the user-provided credentials to Cisco ISE for authentication.

22
Multi-Selecthard

Which THREE of the following items are verified by ISE when a guest attempts to authenticate?

Select 3 answers
A.Account expiration date.
B.The physical location of the NAD.
C.The user's browser version.
D.Password credentials.
E.Account status (e.g., Approved, Pending, Disabled).
AnswersA, D, E

Required check to ensure access is still valid.

Why this answer

ISE checks the validity of the account (status), whether the account has expired, and if the specific credentials provided match the stored record.

23
Multi-Selectmedium

Which TWO of the following are valid ways to provide access to a guest user?

Select 2 answers
A.Bypassing login via a Hotspot portal.
B.Authentication via the Guest Portal using username/password.
C.Connecting via VPN tunnel only.
D.Using a static IP assigned by the administrator.
E.Authenticating via the CLI on the NAD.
AnswersA, B

Standard click-through access.

Why this answer

Guests can be authenticated via their own credentials (Guest Portal) or by simply accepting terms (Hotspot Portal).

24
MCQmedium

Which component is responsible for the actual redirection of the guest user's browser in a CWA flow?

A.The Cisco ISE Policy Service Node (PSN)
B.The Network Access Device (NAD)
C.The endpoint's default browser
D.The Guest Portal application
AnswerB

The switch intercepts the traffic and returns a 302 redirect.

Why this answer

The switch (NAD) performs the redirection based on the 'url-redirect' attribute provided by ISE in the RADIUS access-accept.

25
MCQhard

You are implementing a Guest flow where you need to track the physical location of the guest. Which attribute is best used to identify the location of the request?

A.Framed-IP-Address
B.Called-Station-ID
C.Calling-Station-ID
D.NAS-IP-Address
AnswerB

This identifies the switch port or SSID.

Why this answer

The 'Called-Station-ID' attribute, which typically contains the SSID or the Switch Port ID, allows ISE to identify where the connection attempt originated.

26
MCQhard

You are troubleshooting a scenario where guest users are not being redirected when connecting to an open SSID. The WLC reports that the client is stuck in the 'Webauth' state but the portal never loads. Which component should you verify first?

A.Increase the idle timeout on the WLC's WLAN configuration.
B.Verify the WLC's 'Web Auth Redirect' configuration and ensure the 'Virtual Gateway' address is reachable.
C.Re-import the Guest Portal certificate on the WLC.
D.Check if the client can resolve the ISE FQDN via DNS.
AnswerD

For the redirect to occur, the client must be able to resolve the ISE FQDN to an IP address; otherwise, the browser will timeout.

Why this answer

If the client is in the Webauth state on the WLC but the portal doesn't load, the issue is typically that the DNS resolution of the ISE FQDN is failing for the client or the WLC is not passing the redirect URL correctly.

27
MCQmedium

You are configuring a Guest Portal that requires sponsor approval. What does the 'Sponsor Approval' setting inside the portal configuration actually do?

A.It automatically emails the sponsor.
B.It sets the guest account status to 'Pending' until approved.
C.It sends a RADIUS request to the sponsor's device.
D.It allows the guest to bypass the login screen.
AnswerB

This is the core functional change for the account.

Why this answer

It forces the guest account status to be 'pending' until a sponsor manually updates it to 'approved', preventing network access until that happens.

28
MCQhard

In a CWA flow, what is the significance of the 'cisco-av-pair = url-redirect-acl' attribute?

A.It defines the URL to which the user is redirected.
B.It triggers the CoA process.
C.It defines the guest group permissions.
D.It specifies the name of the ACL on the NAD that defines traffic to be intercepted.
AnswerD

This is the correct function of the redirect-acl attribute.

Why this answer

This attribute tells the NAD which ACL to use to determine which packets should be redirected and which should be allowed to proceed without redirection (e.g., DNS, DHCP, and traffic to ISE).

29
MCQeasy

Which protocol does the Cisco ISE use to inform the NAD that a guest user's session state has changed (e.g., from 'redirect' to 'authenticated')?

AnswerA

CoA is the standard RADIUS extension for this.

Why this answer

Change of Authorization (CoA) is the mechanism used by RADIUS to update an active session.

30
MCQhard

A Guest user is stuck in a loop and cannot access the internet after authenticating. The NAD log shows the session is bouncing between the redirect state and authorized state. What is the most likely cause?

A.The guest user account is expired.
B.The switch is configured for redundant ISE nodes.
C.The Redirect ACL does not permit traffic to the ISE PSN IP.
D.The CoA port is blocked by a firewall.
AnswerC

If traffic to ISE is captured by the redirect rule, a loop occurs.

Why this answer

If the Redirect ACL is not properly configured to exclude the ISE PSN IP, the traffic to the ISE portal might get redirected again, causing a loop.

31
Multi-Selecthard

Which TWO of the following tasks are performed within the Sponsor Portal?

Select 2 answers
A.Mapping VLANs to specific guest SSIDs.
B.Configuring global portal branding.
C.Defining RADIUS shared secrets.
D.Creating new guest accounts.
E.Approving guest access requests.
AnswersD, E

Sponsors can manually create guest accounts for visitors.

Why this answer

The sponsor portal is used by internal users to manage the lifecycle of guest accounts, such as creating, approving, or extending them.

32
MCQeasy

A network administrator is configuring Central Web Authentication (CWA) and needs to ensure that the initial redirect is handled correctly by the switch. Which attribute must the Cisco ISE send to the network access device (NAD) to trigger the redirection?

A.cisco-av-pair = redirect-url=http://ise.example.com
B.cisco-av-pair = url-redirect=https://ise.example.com:8443/guestportal/gateway
C.cisco-av-pair = redirect-to=https://ise.example.com
D.cisco-av-pair = url-redirect-acl=REDIRECT_ACL
AnswerB

This is the correct syntax for the redirect URL attribute.

Why this answer

The Cisco-AV-Pair 'url-redirect' is the standard attribute used in a RADIUS Accept message to inform the switch to redirect web traffic to the ISE guest portal.

33
MCQmedium

You need to allow guest users to access specific internal resources (like a printer) while they are connected to the Guest network. How do you configure this in ISE?

A.Enable Guest VLAN assignment.
B.Assign a downloadable ACL (dACL) in the Authorization Profile.
C.Modify the Redirect ACL on the switch.
D.Configure a port-based ACL on the switch interface.
AnswerB

dACLs provide granular control for the session.

Why this answer

Authorization Profiles define the permissions for the user. By assigning a specific dACL that permits access to the printer, you allow that traffic.

34
MCQmedium

When configuring an LWA portal, you notice that the HTTP traffic is not being redirected. What is a primary requirement for LWA that differs from CWA?

A.The NAD must have the 'ip http server' enabled.
B.The endpoint must be statically assigned an IP.
C.A redirect ACL must be applied to the ISE interface.
D.The ISE node must be the default gateway.
AnswerA

LWA requires the local switch web server to intercept HTTP requests.

Why this answer

LWA requires the NAD to act as the web server for the captive portal, meaning the switch handles the HTTP request interception directly, unlike CWA where the endpoint is redirected to ISE.

35
MCQhard

What is the purpose of the 'Guest Flow' setting in the Authorization Profile?

A.It defines the session timeout.
B.It enables MAC caching.
C.It defines the Guest Group.
D.It tells the ISE to trigger the Guest Portal.
AnswerD

This setting links the profile to the specific guest portal type.

Why this answer

The Guest Flow setting determines how the guest session is handled by the ISE, specifically linking the authorization profile to the appropriate portal type.

36
Multi-Selectmedium

Which TWO of the following settings are available for customizing the guest portal login page?

Select 2 answers
A.Selection of the switch interface.
B.Inclusion of a mandatory AUP checkbox.
C.Direct editing of the Apache server config files.
D.Configuration of the RADIUS shared secret.
E.Modification of the login form header and footer text.
AnswersB, E

This is a configurable portal option.

Why this answer

ISE portals allow for extensive customization of the UI, including the text displayed and the inclusion of specific fields like terms of use or registration forms.

37
MCQeasy

In the context of the Guest flow, what is the purpose of the 'Guest Types' configuration?

A.To manage the list of sponsors.
B.To define the portal look and feel.
C.To define attributes like account lifetime and access policies for guest accounts.
D.To configure the RADIUS server settings.
AnswerC

This is the primary function of guest types.

Why this answer

Guest types allow you to define common parameters like account duration, password requirements, and access permissions that can be applied to guest accounts.

38
MCQmedium

You are reviewing the ISE logs and see that the Guest Portal authentication is failing. Where should you look to find the exact reason for the failure?

A.Operations > RADIUS Livelogs
B.Monitoring > Reports > Guest
C.Policy > Policy Sets
D.Administration > System > Logging
AnswerA

This is the primary tool for troubleshooting auth failures.

Why this answer

The 'Live Logs' in ISE provide real-time visibility into authentication attempts, including the specific failure reason (e.g., 'invalid credentials', 'user account expired').

39
MCQeasy

A guest user successfully authenticates at the sponsor portal but cannot access the internet. You notice the session remains in the 'Pending' state. What is the most likely cause?

A.The ISE node is not reachable via the DNS server specified in the guest VLAN.
B.The sponsor has not approved the guest account request.
C.The authorization policy is missing a 'permit access' rule for the guest account.
D.The guest password policy is incorrectly configured in the Guest Portal settings.
AnswerB

When an account is created with sponsor approval required, it remains in a pending state until the sponsor approves it via the sponsor portal.

Why this answer

The 'Pending' state indicates that the sponsor or an administrator has not yet approved the account creation request, which is a common security feature in guest access flows.

40
Multi-Selecteasy

Which THREE components are part of the 'Guest Access' workflow in Cisco ISE?

Select 3 answers
A.ISE Policy Sets.
B.Device Sensor Service.
C.Guest Portal.
D.Active Directory Join.
E.Sponsor Portal.
AnswersA, C, E

These define the authentication and authorization rules for the guest session.

Why this answer

The guest workflow typically involves the guest user, a sponsor who validates the access, and the ISE engine that enforces the policy.

41
Multi-Selectmedium

Which TWO of the following are mandatory components for a CWA deployment?

Select 2 answers
A.A WLC with WPA3-Enterprise.
B.A local user database on the switch.
C.A redirect ACL configured on the NAD.
D.A static IP address for all guest clients.
E.A guest portal configured in ISE.
AnswersC, E

Mandatory for traffic interception.

Why this answer

CWA requires a properly configured redirect ACL on the NAD and a corresponding authorization profile in ISE that points the client to the portal.

Ready to test yourself?

Try a timed practice session using only Web Auth And Guest Services questions.