
CiscoCertified Network Professional Security
Domain 6Objective 3
6.3 Configure Network Access Control Mechanisms Such as 802.1X and MAB with Cisco Identity Services Engine 350-701 Practice Questions (Page 1)
Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
7concepts
15%of the exam
Questions 1–5
- 1
A network engineer is configuring a switch for 802.1X with ISE. The switch has the following configuration: 'aaa new-model', 'radius server ISE', 'address ipv4 10.1.1.10', 'key cisco123', 'aaa authentication dot1x default group radius', 'aaa authorization network default group radius'. The ISE policy set is configured correctly. Users can authenticate and receive the correct VLAN. However, the switch logs show periodic 'RADIUS server ISE' timeouts. What is the most likely cause?
Select an answer first - 2
Which protocol does Cisco ISE use to communicate with network access devices when acting as the authentication server for 802.1X and MAB?
Select an answer first - 3
In Cisco ISE, what is the purpose of a policy set?
Select an answer first - 4
What is the purpose of the 'radius server' configuration on a Cisco network device when integrating with ISE?
Select an answer first - 5
A user's PC fails 802.1X authentication on a wired port. The switch shows the port in 'unauthorized' state. ISE live logs show the authentication failed with the reason 'Supplicant stopped responding to EAP-Request/Identity'. The user's PC is running the Cisco AnyConnect supplicant. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.