nerdexam
Cisco

300-420 · Question #300

Which two statements are true regarding Cisco ISE? (Choose two.)

The correct answer is B. ISE can provide data about when a specific device connected to the network. C. ISE plays a critical role in SD-Access.. Cisco ISE collects detailed connection data for devices and plays a fundamental role in SD-Access for policy enforcement and network segmentation.

Network Services

Question

Which two statements are true regarding Cisco ISE? (Choose two.)

Options

  • AWithout integration with any other product ISE can track the actual physical location of a wireless
  • BISE can provide data about when a specific device connected to the network.
  • CISE plays a critical role in SD-Access.
  • DThe major business outcomes of ISE are enhanced user experience and secure VLAN
  • EAn ISE deployment requires only a Cisco Access Control System appliance.

How the community answered

(21 responses)
  • B
    90% (19)
  • D
    5% (1)
  • E
    5% (1)

Why each option

Cisco ISE collects detailed connection data for devices and plays a fundamental role in SD-Access for policy enforcement and network segmentation.

AWithout integration with any other product ISE can track the actual physical location of a wireless

ISE typically requires integration with other systems like wireless LAN controllers (WLCs) and location services to accurately track the physical location of wireless devices, it cannot do this standalone.

BISE can provide data about when a specific device connected to the network.Correct

Cisco ISE functions as a centralized policy enforcement platform that records and correlates contextual data, including when specific devices connect to the network, providing comprehensive visibility and reporting.

CISE plays a critical role in SD-Access.Correct

In Cisco SD-Access, ISE is the policy engine responsible for assigning Scalable Group Tags (SGTs) to users and devices, enabling micro-segmentation and consistent policy application across the fabric.

DThe major business outcomes of ISE are enhanced user experience and secure VLAN

While ISE enhances user experience and secures network access, 'secure VLAN' is a specific and limited outcome; ISE's major business outcomes are broader, including compliance, threat containment, and secure network access control.

EAn ISE deployment requires only a Cisco Access Control System appliance.

An ISE deployment requires Cisco ISE appliances or virtual machines, not a Cisco Access Control System (ACS) appliance, which is an older, distinct product for network access control.

Concept tested: Cisco ISE capabilities and integration

Source: https://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html

Topics

#Cisco ISE#Network Access Control#AAA#SD-Access

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice