Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)

⚠ Common exam trap

The trap here is selecting pxGrid or MAB as if they enforced segmentation, when in fact SGTs plus CoA are the mechanisms that dynamically tag and reauthorize endpoint traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes

Security Group Tags assigned by ISE and enforced by TrustSec-capable switches provide identity-based segmentation independent of VLANs, while Change of Authorization allows ISE to dynamically update authorization results as identity or posture changes. Together they deliver dynamic, identity-driven access across wired and wireless, which static VLANs, MAB, or pxGrid alone cannot achieve.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes

    Why this is correct

    CoA lets ISE push new authorization results, such as a new SGT or VLAN, to the network access device when posture or identity changes. This enables dynamic enforcement without reconnecting the endpoint. Combined with SGTs, CoA ensures segmentation stays current as conditions change, which is essential for a Zero Trust model across wired and wireless.

  • ✗

    Cisco Platform Exchange Grid (pxGrid) to share context between ISE and third-party security tools

    Why it's wrong here

    pxGrid enables integration and context sharing with ecosystem partners such as firewalls and SIEMs, which is valuable but not the mechanism that enforces identity-based segmentation on campus switches. The requirement is dynamic segmentation enforcement, which is delivered by SGTs and CoA. pxGrid alone does not tag or segment endpoint traffic, so it is not a correct choice here.

  • ✓

    Security Group Tags (SGTs) applied via ISE and enforced by Cisco TrustSec-capable switches

    Why this is correct

    SGTs allow ISE to assign a tag based on identity and posture, and TrustSec-capable switches enforce Security Group ACLs between tags. This provides dynamic, identity-based segmentation independent of VLAN topology and works across wired and wireless, directly meeting the Zero Trust requirement. It is the core Cisco segmentation mechanism for this scenario.

  • ✗

    MAC Authentication Bypass (MAB) as the primary authentication method for all endpoints

    Why it's wrong here

    MAB authenticates by MAC address, which is easily spoofed and provides weak identity assurance. Using it as the primary method for all endpoints undermines Zero Trust, which requires strong identity. MAB is typically a fallback for devices that cannot run 802.1X, not the foundation of a dynamic segmentation design, so it does not meet the requirement.

  • ✗

    Static VLAN assignment per access switch port to isolate user groups

    Why it's wrong here

    Static VLANs are the traditional segmentation method and are explicitly what the architect wants to avoid relying on. They do not adapt to identity or posture changes and are cumbersome across wired and wireless. While VLANs may still exist, they are not the dynamic identity-based mechanism required here, so this option does not satisfy the design goal.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.