350-401 Security Practice Question
A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)
⚠ Common exam trap
The trap here is selecting pxGrid or MAB as if they enforced segmentation, when in fact SGTs plus CoA are the mechanisms that dynamically tag and reauthorize endpoint traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes
Security Group Tags assigned by ISE and enforced by TrustSec-capable switches provide identity-based segmentation independent of VLANs, while Change of Authorization allows ISE to dynamically update authorization results as identity or posture changes. Together they deliver dynamic, identity-driven access across wired and wireless, which static VLANs, MAB, or pxGrid alone cannot achieve.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes
Why this is correct
CoA lets ISE push new authorization results, such as a new SGT or VLAN, to the network access device when posture or identity changes. This enables dynamic enforcement without reconnecting the endpoint. Combined with SGTs, CoA ensures segmentation stays current as conditions change, which is essential for a Zero Trust model across wired and wireless.
- ✗
Cisco Platform Exchange Grid (pxGrid) to share context between ISE and third-party security tools
Why it's wrong here
pxGrid enables integration and context sharing with ecosystem partners such as firewalls and SIEMs, which is valuable but not the mechanism that enforces identity-based segmentation on campus switches. The requirement is dynamic segmentation enforcement, which is delivered by SGTs and CoA. pxGrid alone does not tag or segment endpoint traffic, so it is not a correct choice here.
- ✓
Security Group Tags (SGTs) applied via ISE and enforced by Cisco TrustSec-capable switches
Why this is correct
SGTs allow ISE to assign a tag based on identity and posture, and TrustSec-capable switches enforce Security Group ACLs between tags. This provides dynamic, identity-based segmentation independent of VLAN topology and works across wired and wireless, directly meeting the Zero Trust requirement. It is the core Cisco segmentation mechanism for this scenario.
- ✗
MAC Authentication Bypass (MAB) as the primary authentication method for all endpoints
Why it's wrong here
MAB authenticates by MAC address, which is easily spoofed and provides weak identity assurance. Using it as the primary method for all endpoints undermines Zero Trust, which requires strong identity. MAB is typically a fallback for devices that cannot run 802.1X, not the foundation of a dynamic segmentation design, so it does not meet the requirement.
- ✗
Static VLAN assignment per access switch port to isolate user groups
Why it's wrong here
Static VLANs are the traditional segmentation method and are explicitly what the architect wants to avoid relying on. They do not adapt to identity or posture changes and are cumbersome across wired and wireless. While VLANs may still exist, they are not the dynamic identity-based mechanism required here, so this option does not satisfy the design goal.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.