500-651 · Question #44
Which feature of Cisco AnyConnect allows pre-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?
The correct answer is A. Secure Layer-2 Network Access. Secure Layer-2 Network Access is correct because it encompasses Cisco AnyConnect's Start Before Logon (SBL) capability, which establishes the VPN tunnel before the Windows desktop loads, enabling pre-login domain authentication. This same feature also supports Single Sign-On…
Question
Which feature of Cisco AnyConnect allows pre-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?
Options
- ASecure Layer-2 Network Access
- BFlexible AAA Options
- CDifferentiated Mobile Access
- DTrusted Network Detection
How the community answered
(41 responses)- A90% (37)
- B5% (2)
- C2% (1)
- D2% (1)
Explanation
Secure Layer-2 Network Access is correct because it encompasses Cisco AnyConnect's Start Before Logon (SBL) capability, which establishes the VPN tunnel before the Windows desktop loads, enabling pre-login domain authentication. This same feature also supports Single Sign-On (SSO) by passing Windows logon credentials directly to the VPN, so users authenticate once to both Windows and the network simultaneously.
B (Flexible AAA Options) is wrong - this describes support for multiple authentication backends (RADIUS, LDAP, certificates), not the mechanism for pre-login or Windows credential SSO.
C (Differentiated Mobile Access) is wrong - this refers to applying different access policies for mobile devices (iOS, Android) versus desktops, unrelated to logon timing or credential sharing.
D (Trusted Network Detection) is wrong - TND auto-connects or disconnects the VPN based on whether the client is already on a trusted corporate network; it has nothing to do with pre-login authentication.
Memory tip: Think "Secure Layer-2 = Sign in before Login" - the two S/L pairs link the feature name to its defining behavior: authenticating at the secure layer before the Windows login screen clears.
Topics
Community Discussion
No community discussion yet for this question.