nerdexam
Cisco

500-651 · Question #44

Which feature of Cisco AnyConnect allows pre-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?

The correct answer is A. Secure Layer-2 Network Access. Secure Layer-2 Network Access is correct because it encompasses Cisco AnyConnect's Start Before Logon (SBL) capability, which establishes the VPN tunnel before the Windows desktop loads, enabling pre-login domain authentication. This same feature also supports Single Sign-On…

Endpoint Security

Question

Which feature of Cisco AnyConnect allows pre-login authentication using windows machines, or single sign-on user authentication using Windows logon credentials?

Options

  • ASecure Layer-2 Network Access
  • BFlexible AAA Options
  • CDifferentiated Mobile Access
  • DTrusted Network Detection

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Secure Layer-2 Network Access is correct because it encompasses Cisco AnyConnect's Start Before Logon (SBL) capability, which establishes the VPN tunnel before the Windows desktop loads, enabling pre-login domain authentication. This same feature also supports Single Sign-On (SSO) by passing Windows logon credentials directly to the VPN, so users authenticate once to both Windows and the network simultaneously.

B (Flexible AAA Options) is wrong - this describes support for multiple authentication backends (RADIUS, LDAP, certificates), not the mechanism for pre-login or Windows credential SSO.

C (Differentiated Mobile Access) is wrong - this refers to applying different access policies for mobile devices (iOS, Android) versus desktops, unrelated to logon timing or credential sharing.

D (Trusted Network Detection) is wrong - TND auto-connects or disconnects the VPN based on whether the client is already on a trusted corporate network; it has nothing to do with pre-login authentication.

Memory tip: Think "Secure Layer-2 = Sign in before Login" - the two S/L pairs link the feature name to its defining behavior: authenticating at the secure layer before the Windows login screen clears.

Topics

#AnyConnect Pre-login Authentication#Windows SSO Integration#Secure Layer-2 Access#Network Access Control

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice