Secure Network Access, Visibility, and Enforcement
Drill 20 practice questions focused entirely on Secure Network Access, Visibility, and Enforcement for the Cisco 350-701 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A company wants employees to be able to register and configure their personally owned devices for secure 802.1X access to the corporate WLAN without help-desk involvement. Requirements: each device must automatically receive the correct supplicant configuration and be issued a unique X.509 certificate for EAP-TLS authentication. Which Cisco ISE capability satisfies these BYOD requirements?
An enterprise uses Cisco ISE for 802.1X on wired switches. When an endpoint's profile changes and it must move to a different dynamic VLAN, the administrator notices that some thin clients do not request a new DHCP address after ISE pushes the policy change, leaving them stranded on the old subnet. Which Change of Authorization (CoA) type should ISE issue to force these endpoints onto the new VLAN while triggering a fresh DHCP request without requiring a full re-authentication handshake?
An enterprise runs Cisco ISE with profiling enabled. A workstation initially connects and is placed in a limited VLAN because ISE has only collected partial DHCP and RADIUS attributes. Moments later, ISE receives additional CDP and DHCP data that reclassifies the device into a trusted 'Corporate-Workstation' profile with a more permissive authorization profile. Which mechanism allows ISE to enforce the new authorization result on the switch port WITHOUT requiring the endpoint to physically disconnect and reconnect?
A security architect wants to ensure that only corporate laptops that meet defined security requirements (disk encryption enabled, endpoint protection running, and OS patched) can access sensitive internal applications. Endpoints that fall out of compliance should automatically be blocked from those applications until they are remediated, without an administrator manually reviewing each device. Which benefit of device compliance enforcement best describes what the architect is trying to achieve?
A security analyst notices that a single internal host is generating an unusually high volume of DNS queries to a rarely-used external domain. The queries contain long, seemingly random subdomain strings, and the corresponding TXT responses are also large. No other protocols show anomalous activity from this host. Which threat does this behavior most likely indicate?
A network engineer is deploying wired 802.1X on Catalyst access switches so that corporate laptops authenticate against Cisco ISE before gaining network access. During testing, the laptops send EAP frames to the switch, which then relays the authentication exchange to ISE using RADIUS. In this 802.1X architecture, what is the specific role played by the switch?
A retail company wants to offer WiFi to walk-in customers with minimal friction: users should get immediate internet access after simply accepting an acceptable use policy, with no employee involvement and no pre-created accounts. The security team still wants a record that each user agreed to the terms. Which Cisco ISE guest access type best meets these requirements?
A security analyst reviewing telemetry notices that a compromised internal workstation is sending large, encrypted POST requests to an external host on TCP port 443 at regular intervals throughout the night. The destination domain was registered only days ago and receives far more upload traffic from the host than it returns. Which data exfiltration technique does this activity most strongly indicate?
A security analyst reviewing NetFlow telemetry notices a workstation generating a continuous stream of unusually large ICMP echo-request packets to a single external IP address, with abnormally high data volume in the payload and consistent bidirectional traffic over several hours. No ping monitoring tools are configured on this host. Which exfiltration technique does this behavior most likely indicate?
A security analyst reviewing Secure Network Analytics flow records notices that several internal hosts are maintaining persistent outbound TCP sessions to an external server on port 6667. The sessions show low-volume, bidirectional text-based traffic with periodic short bursts, and the destination is not on any approved application list. Which exfiltration or command-and-control technique is most consistent with this behavior?
A retail company wants to offer wireless internet to visitors in its stores. Management requires that guests provide their own contact details (name, email, phone) to create their own accounts without needing an employee to approve or vouch for them, and that guests receive credentials automatically. Which Cisco ISE guest portal type best meets these requirements?
A security engineer is deploying Cisco ISE posture assessment for corporate laptops. Employees authenticate successfully via 802.1X, but the engineer notices that noncompliant endpoints are still receiving full network access before posture results are evaluated. What is the correct design approach so that endpoints are restricted until posture completes?
A hospital deploys Cisco ISE to enforce access policies on wired ports. Medical IoT devices such as infusion pumps cannot run a supplicant and are onboarded via MAB. Once ISE profiles a device as a known infusion pump, it must immediately move that endpoint into a restricted medical VLAN without requiring the device to be unplugged or manually reset. Which ISE capability makes this dynamic re-enforcement possible after the initial MAB authorization?
A hospital is deploying hundreds of IP-based patient monitors, IP cameras, and medical carts that cannot run an 802.1X supplicant. Security wants to ensure these devices are automatically recognized by device type and placed into the correct access policy without manual switch port configuration, and wants an inventory of every connected device. Which ISE capability directly delivers this outcome?
A network administrator is deploying Cisco ISE profiling to automatically classify a fleet of newly purchased IP phones and printers. Many of these devices do not support 802.1X and communicate primarily via DHCP and SNMP. The administrator wants the most accurate device classification without deploying agents on the endpoints. Which combination of profiling probes should be enabled to gather the richest identity attributes for these devices?
A network administrator is deploying 802.1X on access switch ports in a branch office. Several network printers and IP cameras on these ports do not support an 802.1X supplicant and therefore fail authentication, leaving them without network access. The administrator must allow these headless devices onto the network while still enforcing 802.1X for endpoints that support it. Which access control mechanism should be configured on the switch ports to meet this requirement?
A security operations team wants to detect anomalous behavior across the enterprise network without deploying packet-capture appliances on every segment. They plan to collect flow telemetry from routers and switches into a network traffic analysis platform. Which benefit of network telemetry most directly supports their goal of spotting deviations from normal traffic patterns?
A security architect wants to detect malware communication inside TLS-encrypted flows across the campus network without decrypting the traffic and without deploying inline devices. The team already exports NetFlow from Catalyst switches to Cisco Secure Network Analytics (Secure Network Analytics). Which capability should the architect enable to meet this requirement?
A security team at a mid-sized company has firewalls at the internet edge but reports that an attacker moved undetected between internal servers for weeks before being discovered. Management asks the team to improve internal visibility without deploying inline security appliances on every internal link. The team decides to enable NetFlow export from internal switches and routers to a flow-analysis collector. Which benefit of network telemetry BEST addresses the team's specific problem?
A company runs Cisco ISE and must perform posture assessment on two groups: full-time employees using corporate laptops, and short-term contractors who bring unmanaged personal laptops for a two-week engagement. The security team wants contractors checked for antivirus and OS patch level without permanently installing software on their machines, while employees should have a persistent posture agent that continuously monitors compliance. Which approach meets both requirements?
More 350-701 practice
Keep going with the other Cisco CCNP Security SCOR (350-701) domains, or take a full timed mock exam.
← Back to 350-701 overview