nerdexam
Cisco

500-651 · Question #13

Which feature of Cisco AnyConnect allows pie-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?

The correct answer is A. Secure Layer-2 Network Access. Secure Layer-2 Network Access (Option A) is correct because this AnyConnect feature leverages IEEE 802.1X authentication, which operates at Layer 2 - before the OS fully loads - enabling pre-login (the question's "pie-login") machine authentication and Single Sign-On (SSO)…

Endpoint Security

Question

Which feature of Cisco AnyConnect allows pie-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?

Options

  • ASecure Layer-2 Network Access
  • BFlexible AAA Options
  • CDifferentiated Mobile Access
  • DTrusted Network Detection

How the community answered

(65 responses)
  • A
    92% (60)
  • B
    5% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Secure Layer-2 Network Access (Option A) is correct because this AnyConnect feature leverages IEEE 802.1X authentication, which operates at Layer 2 - before the OS fully loads - enabling pre-login (the question's "pie-login") machine authentication and Single Sign-On (SSO) using Windows logon credentials. This is delivered through AnyConnect's Network Access Manager component, which can authenticate users or machines to wired/wireless networks using Windows credentials seamlessly.

Why the distractors are wrong:

  • B. Flexible AAA Options refers to AnyConnect's support for multiple authentication backends (RADIUS, LDAP, etc.) - it's about what authenticates users, not when or how Windows credentials are reused.
  • C. Differentiated Mobile Access is about applying different access policies or profiles to mobile vs. desktop clients - unrelated to pre-login auth.
  • D. Trusted Network Detection automatically connects or disconnects the VPN based on whether the client is on a trusted (corporate) network - a connectivity policy feature, not an authentication mechanism.

Memory tip: Think "Layer-2 = before you log in." 802.1X wired/wireless auth happens at Layer 2, which is below the OS login screen - so Secure Layer-2 Network Access is the only option that can touch Windows credentials at the pre-login stage.

Topics

#Cisco AnyConnect#Pre-login Authentication#Windows SSO#Layer-2 Network Access

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice