300-420 · Question #278
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
The correct answer is B. traffic generated by the device C. RADIUS attributes F. user authentication to the ISE. Cisco ISE gathers information about connected devices by passively analyzing network traffic, processing various RADIUS attributes received during authentication, and directly from user authentication events to the ISE platform itself.
Question
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
Options
- Anetwork servers the device has accessed
- Btraffic generated by the device
- CRADIUS attributes
- DRPC mechanism via HTTPS
- ESMTP agents
- Fuser authentication to the ISE
How the community answered
(63 responses)- A5% (3)
- B90% (57)
- D2% (1)
- E3% (2)
Why each option
Cisco ISE gathers information about connected devices by passively analyzing network traffic, processing various RADIUS attributes received during authentication, and directly from user authentication events to the ISE platform itself.
While ISE might infer some context from connections to network servers, it is not a primary or direct mechanism for ISE to learn specific device attributes in the same way as passive traffic analysis or RADIUS.
ISE passively monitors network traffic, such as DHCP, HTTP, DNS, and NetFlow, to profile endpoints based on observed communication patterns and protocol details.
During RADIUS authentication, network access devices send various RADIUS attributes to ISE, which are crucial for device profiling, policy decisions, and identifying endpoint characteristics.
RPC mechanism via HTTPS is not a standard, primary method for Cisco ISE to profile endpoints; common profiling methods rely on protocols like DHCP, HTTP, DNS, and NetFlow.
SMTP agents are related to email services and are not a native or primary mechanism used by Cisco ISE to discover or profile network endpoints.
When users or devices authenticate directly through ISE, the authentication process itself provides ISE with details about the requesting endpoint, including its MAC address and other identifying information.
Concept tested: Cisco ISE endpoint profiling methods
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_guide_31/b_ise_admin_guide_31_chapter_01000.html
Topics
Community Discussion
No community discussion yet for this question.