Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring a remote access VPN using Cisco…

A network engineer is configuring a remote access VPN using Cisco AnyConnect on an ASA. The engineer wants to use certificate-based authentication. The ASA is configured with a CA server. After configuration, users can connect, but they are prompted for a username and password instead of using certificates. The engineer checks the ASA configuration and sees that the tunnel group has authentication method set to AAA. What should the engineer do to fix this?

⚠ Common exam trap

Cisco often tests the distinction between tunnel group authentication (which controls the credential prompt) and group policy authorization (which applies after authentication), leading candidates to mistakenly configure the group policy instead of the tunnel group.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the tunnel group authentication method to certificate.

The tunnel group authentication method determines how users are authenticated for the VPN connection. When set to AAA, the ASA prompts for a username and password, bypassing certificate-based authentication. Changing it to 'certificate' tells the ASA to use the client certificate for authentication, which matches the requirement for certificate-based authentication with AnyConnect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Re-enroll the CA certificate on the ASA.

    Why it's wrong here

    Re-enrolling the CA certificate on the ASA is unnecessary because end users are already successfully completing the TLS handshake with the ASA, which proves that the CA and its certificate are valid and trusted. Certificate re-enrollment addresses issues like expired roots or mismatched trust anchors, but the current symptom is specifically that users connect but are not authenticated via their certificates. The validation failure occurs after the TLS session is established, so the problem lies in how the ASA decides to authenticate the user, not in the PKI trust chain.

  • ✗

    Change the connection profile to use the correct group.

    Why it's wrong here

    Changing the connection profile (also known as tunnel group) to the correct group does not fix the authentication method, because the connection profile may be correct while its authentication setting is misconfigured. Each tunnel group independently contains both the identity to use for matching and the AAA server group or certificate method for validating users. Selecting a different group would only be relevant if the current group lacked the proper certificate-mapping attributes, but that is not the root cause here; the authentication method itself must be flipped to certificate to allow the certificate to be used as the credential.

  • ✗

    Configure the group policy to require certificates.

    Why it's wrong here

    Configuring the group policy to require certificates is not a valid or supported approach, because group policies control post-authentication authorization attributes such as ACLs, split-tunnel settings, and address pools, not the authentication mechanism. In Cisco ASA AnyConnect deployments, the authentication method is defined solely at the tunnel group level, either as AAA, certificate, or a combination, and there is no group-policy option to 'require certificates'. Even if such a setting existed, it would not alter the tunnel group's actual authentication process, so it would have no effect on the symptom.

  • ✓

    Change the tunnel group authentication method to certificate.

    Why this is correct

    Changing the tunnel group authentication method to certificate is the correct action because the tunnel group is where the ASA determines whether to accept usernames/passwords, client certificates, or both. Once the AnyConnect client presents a certificate, the ASA must be configured with the authentication method of 'certificate' (or 'both') in the matching tunnel group to validate that certificate and map it to a user identity. Without this setting, the ASA falls back to its default AAA login prompt, ignoring the client's certificate and causing the exact behavior seen where users can establish a network connection but cannot authenticate.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.