nerdexam
Cisco

300-420 · Question #277

Which two statements are true regarding Cisco ISE? (Choose two.)

The correct answer is A. The number of logs that ISE can retain is determined by your disk space B. ISE supports IPv6 downloadable ACLs. Cisco ISE's log retention capability is directly limited by available disk space, and the platform fully supports the use of IPv6 within downloadable access control lists (DACLs).

Network Services

Question

Which two statements are true regarding Cisco ISE? (Choose two.)

Options

  • AThe number of logs that ISE can retain is determined by your disk space
  • BISE supports IPv6 downloadable ACLs
  • CIn two-node standalone ISE deployments, failover must be done manually
  • DISE supports up to 100 Policy Services Nodes
  • EISE can detected endpoints whose addresses have been translated via NAT
  • FIn distributed deployments, failover from primary to secondary Policy Administration Nodes

How the community answered

(36 responses)
  • A
    92% (33)
  • C
    6% (2)
  • D
    3% (1)

Why each option

Cisco ISE's log retention capability is directly limited by available disk space, and the platform fully supports the use of IPv6 within downloadable access control lists (DACLs).

AThe number of logs that ISE can retain is determined by your disk spaceCorrect

The amount of log data that Cisco ISE can store is directly dependent on the disk capacity allocated to the ISE instance, as logs consume storage resources.

BISE supports IPv6 downloadable ACLsCorrect

Cisco ISE has the capability to generate and push Downloadable ACLs (DACLs) that include IPv6 rules, allowing for granular access control for IPv6 traffic based on policy.

CIn two-node standalone ISE deployments, failover must be done manually

In two-node ISE deployments configured for high availability, failover from the primary to the secondary node typically occurs automatically, not manually.

DISE supports up to 100 Policy Services Nodes

Cisco ISE supports a maximum of 50 Policy Service Nodes (PSNs) in a distributed deployment, not 100.

EISE can detected endpoints whose addresses have been translated via NAT

While ISE gathers endpoint information, detecting endpoints whose addresses have been translated via NAT is challenging for ISE, as it primarily sees the NAT device's public IP.

FIn distributed deployments, failover from primary to secondary Policy Administration Nodes

In a distributed deployment, failover from a primary Policy Administration Node (PAN) to a secondary PAN is automatic, but the statement incorrectly refers to failover to a PSN.

Concept tested: Cisco ISE capabilities and limitations

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/admin_guide/b_ise_admin_guide_32/b_ise_admin_guide_32_chapter_0110.html

Topics

#Cisco ISE#ISE Architecture#High Availability#Scalability

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice