nerdexam
Cisco

300-420 · Question #294

Which two options are primary functions of Cisco ISE? (Choose two.)

The correct answer is A. enforcing endpoint compliance with network security policies D. providing information about every device that touches the network. Cisco ISE primarily functions to enforce network security policies by ensuring endpoint compliance and by providing comprehensive visibility and context about every device connecting to the network.

Network Services

Question

Which two options are primary functions of Cisco ISE? (Choose two.)

Options

  • Aenforcing endpoint compliance with network security policies
  • Benabling WAN deployment over any type of connection
  • Cautomatically enabling, disabling or reducing allocated power to certain devices
  • Dproviding information about every device that touches the network
  • Eproviding encryption for any type of mobile devices
  • Fallocating cloud resources

How the community answered

(23 responses)
  • A
    91% (21)
  • E
    4% (1)
  • F
    4% (1)

Why each option

Cisco ISE primarily functions to enforce network security policies by ensuring endpoint compliance and by providing comprehensive visibility and context about every device connecting to the network.

Aenforcing endpoint compliance with network security policiesCorrect

Cisco ISE is a Network Access Control (NAC) solution designed to enforce granular network access policies based on user, device, and posture, ensuring that endpoints comply with defined security standards before gaining network access.

Benabling WAN deployment over any type of connection

Enabling WAN deployment over various connection types is a function typically associated with SD-WAN or other specific WAN technologies, not the primary role of Cisco ISE.

Cautomatically enabling, disabling or reducing allocated power to certain devices

While ISE can influence device access, its primary role does not involve directly managing the power allocation or state of network-connected devices.

Dproviding information about every device that touches the networkCorrect

ISE's profiling capabilities automatically discover and categorize every device connecting to the network, gathering extensive contextual information which is critical for policy enforcement and network visibility.

Eproviding encryption for any type of mobile devices

Cisco ISE integrates with Mobile Device Management (MDM) solutions for posture assessment of mobile devices, but it does not directly provide encryption for these devices.

Fallocating cloud resources

Allocating cloud resources is a responsibility of cloud management platforms and orchestrators, which is outside the core functionality of a network access control system like ISE.

Concept tested: Cisco ISE core functions, NAC capabilities

Source: https://www.cisco.com/c/en/us/products/security/identity-services-engine/what-is-ise.html

Topics

#Cisco ISE#Network Security#Endpoint Compliance#Network Visibility

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice