nerdexam
Cisco

350-701 · Question #754

How does a Cisco Secure Web Appliance integrated with LDAP handle the permissions of a currently logged in Active Directory group member when the Active Directory administrator changes the…

The correct answer is D. The Cisco Secure Web Appliance continues to operate using the permissions that were in effect. When the Cisco Secure Web Appliance authenticates a user via LDAP, it caches the user's group membership and associated permissions at the time of login. Because the SWA does not continuously poll Active Directory for real-time permission changes during an active session, any…

Submitted by yuki_2020· Mar 30, 2026Content Security

Question

How does a Cisco Secure Web Appliance integrated with LDAP handle the permissions of a currently logged in Active Directory group member when the Active Directory administrator changes the permissions of the user's group mid session?

Options

  • AIf the Cisco Secure Client Mobility Client is configured on the endpoint to provide Active Directory
  • BIf the Cisco Secure Web Appliance is configured to receive real-time updates from the Active
  • CThe Cisco Secure Web Appliance terminates the current session and prompts the user to re-
  • DThe Cisco Secure Web Appliance continues to operate using the permissions that were in effect

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • D
    93% (26)

Explanation

When the Cisco Secure Web Appliance authenticates a user via LDAP, it caches the user's group membership and associated permissions at the time of login. Because the SWA does not continuously poll Active Directory for real-time permission changes during an active session, any mid-session changes made by an AD administrator will not take effect until the cached credentials expire and the user re-authenticates - making D correct.

Why the distractors fail:

  • A is wrong because the Cisco Secure Client (a VPN/endpoint agent) is unrelated to how SWA resolves LDAP group permissions during a web proxy session.
  • B is wrong because SWA has no native mechanism to receive real-time push updates from Active Directory mid-session; LDAP is a query-based protocol triggered at authentication, not a streaming event system.
  • C is wrong because SWA does not actively monitor for directory changes and has no built-in trigger to terminate and force re-authentication when group policies change.

Memory tip: Think of LDAP authentication like a ticket - once issued at login, the SWA honors that ticket for the duration of the session regardless of what changes backstage. New rules only apply when a new ticket is issued (i.e., next login after cache expiry).

Topics

#Cisco Secure Web Appliance (WSA)#LDAP/Active Directory Integration#User Permissions#Session Management

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice