Secure Network Access, Visibility, and Enforcement
Free Implementing and Operating Cisco Security Core Technologies practice — 6 questions on Secure Network Access, Visibility, and Enforcement, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
A large enterprise is rolling out 802.1X across 500 access switch ports. To avoid disrupting production traffic while the security team observes which endpoints succeed or fail authentication, the first deployment phase must allow all traffic to pass regardless of the authentication outcome, while still generating authentication events for visibility. Which 802.1X deployment mode should be configured on the ports for this initial phase?
Monitor Mode uses 'authentication open' along with multi-auth host mode so that traffic is permitted regardless of the 802.1X/MAB result, while ISE still logs the authentication attempt and result. This gives visibility into who and what is on the network before any enforcement is turned on, and is the standard first phase of a phased ISE 802.1X deployment.
Question 2 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
An organization has deployed Cisco TrustSec across its core and distribution switches, which support inline SGT tagging in the data plane. However, several legacy access switches and a firewall at the network edge cannot tag frames with an SGT but still need to receive IP-address-to-SGT binding information so that SGACL enforcement can occur downstream. Which protocol is used to propagate these IP-to-SGT bindings to devices that don't support inline tagging?
SXP (SGT Exchange Protocol) is designed specifically to propagate IP-address-to-SGT bindings over TCP to devices, such as legacy switches or firewalls, that cannot perform inline SGT tagging in the data plane. This allows those devices to still enforce SGACLs based on the SGT associated with a source or destination IP.
Question 3 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
A security architect needs to control network device administration so that junior engineers can only run 'show' commands on switches, while senior engineers can execute full configuration commands, with all commands logged individually. Which AAA protocol should be used for device administration, and why?
TACACS+ separates authentication, authorization, and accounting (AAA) into distinct exchanges, enabling granular per-command authorization using command sets/shell profiles on the AAA server (e.g., ISE). It also encrypts the entire packet body, which is important for protecting sensitive device-admin credentials and command data. This makes it the standard choice for device administration (as opposed to RADIUS, which is preferred for network access).
Question 4 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
A network team wants Cisco ISE to identify endpoint types such as IP phones and printers by analyzing traffic flow records (source/destination, ports, byte/packet counts) exported by access switches and routers, without requiring an agent on the endpoint. Which ISE profiling probe is designed to consume this type of data?
The NetFlow probe on ISE ingests NetFlow records exported by network devices, which contain traffic flow metadata (source/destination IP and port, protocol, byte/packet counts). ISE uses this flow behavior data as part of profiling logic to classify endpoint types based on their communication patterns.
Question 5 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
A switch port is configured with both 802.1X and MAC Authentication Bypass (MAB) as fallback, using default dot1x timers. A network printer that does not have an 802.1X supplicant is connected to this port. What is the correct sequence of events on this port?
With 802.1X enabled as the primary method, the switch first sends EAPOL-Request Identity frames. Since the printer has no supplicant, there is no response, and the switch retries based on dot1x max-reauth-req and tx-period timers. After exhausting these retries/timeout, the switch falls back to MAB, using the endpoint's MAC address as the identity sent in a RADIUS Access-Request to ISE.
Question 6 of 6 · Domain 6: Secure Network Access, Visibility, and Enforcement
Cisco Secure Network Analytics (Stealthwatch) detects anomalous, malicious behavior from an endpoint on the network and needs to trigger automatic quarantine of that endpoint through Cisco ISE, without manual SOC intervention, as part of Rapid Threat Containment. Which technology enables Stealthwatch to instruct ISE to quarantine the endpoint's session?
pxGrid provides the context-sharing framework that allows Stealthwatch to send a quarantine/ANC request to ISE. ISE's Adaptive Network Control (ANC) feature then applies a quarantine policy to the endpoint's session, and ISE issues a RADIUS Change of Authorization (CoA) to the network access device to re-authorize the session with restricted access (e.g., a quarantine VLAN or dACL) — this is the core mechanism behind Rapid Threat Containment.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.