500-651 · Question #13
Which feature of Cisco AnyConnect allows pie-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?
The correct answer is A. Secure Layer-2 Network Access. Secure Layer-2 Network Access (Option A) is correct because this AnyConnect feature leverages IEEE 802.1X authentication, which operates at Layer 2 - before the OS fully loads - enabling pre-login (the question's "pie-login") machine authentication and Single Sign-On (SSO)…
Question
Which feature of Cisco AnyConnect allows pie-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?
Options
- ASecure Layer-2 Network Access
- BFlexible AAA Options
- CDifferentiated Mobile Access
- DTrusted Network Detection
How the community answered
(65 responses)- A92% (60)
- B5% (3)
- C2% (1)
- D2% (1)
Explanation
Secure Layer-2 Network Access (Option A) is correct because this AnyConnect feature leverages IEEE 802.1X authentication, which operates at Layer 2 - before the OS fully loads - enabling pre-login (the question's "pie-login") machine authentication and Single Sign-On (SSO) using Windows logon credentials. This is delivered through AnyConnect's Network Access Manager component, which can authenticate users or machines to wired/wireless networks using Windows credentials seamlessly.
Why the distractors are wrong:
- B. Flexible AAA Options refers to AnyConnect's support for multiple authentication backends (RADIUS, LDAP, etc.) - it's about what authenticates users, not when or how Windows credentials are reused.
- C. Differentiated Mobile Access is about applying different access policies or profiles to mobile vs. desktop clients - unrelated to pre-login auth.
- D. Trusted Network Detection automatically connects or disconnects the VPN based on whether the client is on a trusted (corporate) network - a connectivity policy feature, not an authentication mechanism.
Memory tip: Think "Layer-2 = before you log in." 802.1X wired/wireless auth happens at Layer 2, which is below the OS login screen - so Secure Layer-2 Network Access is the only option that can touch Windows credentials at the pre-login stage.
Topics
Community Discussion
No community discussion yet for this question.