
CiscoCertified Network Professional Security
Domain 6Objective 3
6.3 Configure Network Access Control Mechanisms Such as 802.1X and MAB with Cisco Identity Services Engine 350-701 Practice Questions (Page 4)
Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
7concepts
15%of the exam
Questions 16–20
- 16
An enterprise has two user groups: employees and contractors. Both authenticate via 802.1X with PEAP-MSCHAPv2. Employees must get full network access, while contractors must be placed in a guest VLAN. The ISE policy set has a single authentication policy that matches all users. What should the administrator configure to differentiate the authorization result?
Select an answer first - 17
A university is configuring ISE as the RADIUS server for 802.1X on its wireless network. The wireless LAN controller (WLC) has been configured with the ISE IP address and shared secret. When a user attempts to connect, authentication fails. The ISE live logs show 'No matching policy set' for the RADIUS request. What is the most likely cause and the correct fix?
Select an answer first - 18
A user reports that their Windows laptop fails 802.1X authentication on a wired port. The switch shows the port in 'unauthorized' state. ISE live logs show an authentication failure with the reason 'EAP-TLS failed the certificate validation'. The user's certificate is issued by the company CA and is valid. Other users with the same CA can authenticate. What is the most likely cause?
Select an answer first - 19
A company is deploying 802.1X on its access switches. The switches are configured with 'aaa new-model', 'radius server ISE', and 'aaa authentication dot1x default group radius'. The ISE policy set is configured correctly. Users can authenticate, but the authorization result (VLAN) is not applied. What is the most likely cause?
Select an answer first - 20
A company is deploying 802.1X with EAP-FAST on its wireless network. The ISE policy set is configured for EAP-FAST with PAC provisioning enabled. Users can authenticate, but the process is slow because PAC provisioning happens on every authentication. What should the administrator configure to improve performance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.