Hi Yury, 
Firstly, I have to confess that I could not understand how to configure the first method on the wireless controller. Because as I know, a VNS can only bind a WLAN service to only two different Roles (non-authenticated / authenticated). 
Anyway, I tried my best and deleted all custom made CoS and Roles on the EWC, then enforced domain policies from Netsight successfully. Then I configured the VNS as below:

Then, I tested this configuration by connecting two different clients to the same SSID (test-8021x) simultaneously: one of the clients assigned to "Vlan211" and the other assigned to "Vlan311" which are not related to "NOT_Domain_PC" role. They are just assigned to Vlans that NAC sends as radius attributes :
Test client-1 Authentication session:

Test client-2 Authentication session:

I understand from this test that no matter what is chosen in the "Default Roles  >> Authenticated" field, clients are assigned according to radius attribute that NAC sends. 
Is it right ?
Thanks