300-320 · Question #1183
NAC: Simple access control at user and device contextual level. Which features support? (Choose 2)
The correct answer is C. ISE D. NAC agent. Cisco ISE and the NAC agent together provide simple, contextual access control by evaluating user identity and device posture before granting network access.
Question
Options
- Asecure access control
- BTrustSec
- CISE
- DNAC agent
How the community answered
(24 responses)- A8% (2)
- B4% (1)
- C88% (21)
Why each option
Cisco ISE and the NAC agent together provide simple, contextual access control by evaluating user identity and device posture before granting network access.
Secure access control is a generic descriptive concept, not a specific Cisco product or feature that can be selected or deployed to implement NAC.
TrustSec is a Cisco macro-segmentation technology that uses Security Group Tags (SGTs) and Security Group ACLs (SGACLs) for group-based policy enforcement across the network fabric, which is a more advanced architecture layer beyond simple user and device contextual access control.
Cisco Identity Services Engine (ISE) is the core NAC platform that enforces policy-based access control by evaluating user identity, device type, and contextual attributes at the time of network connection. It acts as the policy decision point that grants, denies, or restricts access based on who the user is and what device they are using.
The NAC agent (posture agent) runs on endpoint devices and reports device health and compliance information - such as OS version, antivirus status, and patch level - back to ISE, providing the device-level context required for simple contextual access control decisions.
Concept tested: Cisco NAC components - ISE and posture agent
Source: https://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html
Topics
Community Discussion
No community discussion yet for this question.