nerdexam
Cisco

300-420 · Question #301

How would Cisco ISE handle authentication for your printer that does not have a supplicant?

The correct answer is C. ISE would authenticate the printer using MAB. Cisco ISE authenticates devices like printers that lack an 802.1X supplicant using MAC Authentication Bypass (MAB).

Network Services

Question

How would Cisco ISE handle authentication for your printer that does not have a supplicant?

Options

  • AISE would not authenticate the printer as printers are not subject to ISE authentication
  • BISE would authenticate the printer using 802.1X authentication
  • CISE would authenticate the printer using MAB
  • DISE would authenticate the printer using web authentication
  • EISE would authenticate the printer using MAC RADIUS authentication

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    90% (19)
  • E
    5% (1)

Why each option

Cisco ISE authenticates devices like printers that lack an 802.1X supplicant using MAC Authentication Bypass (MAB).

AISE would not authenticate the printer as printers are not subject to ISE authentication

Printers are network devices subject to ISE authentication and policy enforcement to ensure only authorized devices gain network access.

BISE would authenticate the printer using 802.1X authentication

802.1X authentication requires a supplicant on the end device to exchange EAP messages with the authenticator, which printers typically do not possess.

CISE would authenticate the printer using MABCorrect

MAB allows devices without 802.1X supplicant software, such as printers, IP phones, or surveillance cameras, to be authenticated by Cisco ISE using their MAC addresses against a configured database or identity store.

DISE would authenticate the printer using web authentication

Web authentication requires a device with a web browser for user interaction, making it unsuitable for headless devices like printers.

EISE would authenticate the printer using MAC RADIUS authentication

While MAB uses MAC addresses and RADIUS, 'MAC RADIUS authentication' is not the standard or specific Cisco term; MAB is the correct and widely recognized method for this scenario.

Concept tested: Cisco ISE MAC Authentication Bypass (MAB)

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/ISE_PCI/PCI_ISE_SRND.html

Topics

#Cisco ISE#MAC Authentication Bypass (MAB)#Network Access Control#Endpoint Authentication

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice