Q1. An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal. Which condition must be used when configuring an authorization policy that sets DenyAccess permission?
A.Endpoint Identity Group is Blocklist, and the BYOD state is Registered.
B. Endpoint Identify Group is Blocklist, and the BYOD state is Pending.
C. Endpoint Identity Group is Blocklist, and the BYOD state is Lost.
D. Endpoint Identity Group is Blocklist, and the BYOD state is Reinstate.
Correct Answer: A
Q2. A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps: . An initial MAB request is sent to the Cisco ISE node. . Cisco ISE responds with a URL redirection authorization profile if the user's MAC address is unknown in the endpoint identity store. . The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL. Which authentication must the administrator configure on Cisco ISE?
A.device registration WebAuth
B. WLC with local WebAuth
C. wired NAD with local WebAuth
D. NAD with central WebAuth
Correct Answer: D
Q3. An engineer is unable to use SSH to connect to a switch after adding the required CLI commands to the device to enable TACACS+. The device administration license has been added to Cisco ISE, and the required policies have been created. Which action is needed to enable access to the switch?
A.The ip ssh source-interface command needs to be set on the switch
B. 802.1X authentication needs to be configured on the switch.
C. The RSA keypair used for SSH must be regenerated after enabling TACACS+.
D. The switch needs to be added as a network device in Cisco ISE and set to use TACACS+.
Correct Answer: D
Q4. A user is attempting to register a BYOD device to the Cisco ISE deployment, but needs to use the onboarding policy to request a digital certificate and provision the endpoint. What must be configured to accomplish this task?
A.A native supplicant provisioning policy to redirect them to the BYOD portal for onboarding
B. The Cisco AnyConnect provisioning policy to provision the endpoint for onboarding
C. The BYOD flow to ensure that the endpoint will be provisioned prior to registering
D. The posture provisioning policy to give the endpoint all necessary components prior to registering
Correct Answer: A
$ 39
Reviews
There are no reviews yet.