nerdexam
Cisco

200-301 · Question #1063

A customer wants to provide wireless access to contractors using a guest portal on Cisco ISE. The portal is also used by employees. A solution is implemented, but contractors receive a certificate err

The correct answer is B. Install a trusted third-party certificate on the Cisco ISE.. Contractors receive a certificate error because their personal devices do not trust the certificate presented by the Cisco ISE guest portal, which indicates the need for a publicly trusted certificate on ISE.

Submitted by satoshi_tk· Mar 5, 2026ERROR: Official Exam Domains list was not provided

Question

A customer wants to provide wireless access to contractors using a guest portal on Cisco ISE. The portal is also used by employees. A solution is implemented, but contractors receive a certificate error when they attempt to access the portal. Employees can access the portal without any errors. Which change must be implemented to allow the contractors and employees to access the portal?

Options

  • AInstall an Internal CA signed certificate on the Cisco ISE.
  • BInstall a trusted third-party certificate on the Cisco ISE.
  • CInstall an internal CA signed certificate on the contractor devices.
  • DInstall a trusted third-party certificate on the contractor devices.

How the community answered

(32 responses)
  • A
    19% (6)
  • B
    63% (20)
  • C
    6% (2)
  • D
    13% (4)

Why each option

Contractors receive a certificate error because their personal devices do not trust the certificate presented by the Cisco ISE guest portal, which indicates the need for a publicly trusted certificate on ISE.

AInstall an Internal CA signed certificate on the Cisco ISE.

Installing an Internal CA signed certificate on Cisco ISE would only work if the contractor devices are configured to trust that specific Internal CA, which is unlikely for personal devices.

BInstall a trusted third-party certificate on the Cisco ISE.Correct

Since employees can access the portal, their devices likely trust the internal CA (or the certificate is already publicly trusted for them), but contractors' personal devices do not trust the internal CA, necessitating a publicly trusted third-party certificate on the Cisco ISE to resolve the browser certificate error.

CInstall an internal CA signed certificate on the contractor devices.

Installing an internal CA signed certificate on contractor devices is not scalable or practical, as it requires manual configuration on each contractor's personal device.

DInstall a trusted third-party certificate on the contractor devices.

Certificates are installed on the server (Cisco ISE) to prove its identity to clients; installing a trusted third-party certificate on contractor devices would not resolve a certificate error originating from the server's untrusted certificate.

Concept tested: Cisco ISE guest portal certificate trust

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ISE_admin_guide_23/b_ISE_admin_guide_23_chapter_0100.html#concept_3C1D0F85A23C4713BC65C52296DC2F21

Topics

#Cisco ISE#Guest portal#PKI certificates#Certificate trust

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice