300-715 · Question #105
What should be considered when configuring certificates for BYOD?
The correct answer is C. The CN field is populated with the endpoint host name. In Cisco ISE BYOD certificate provisioning, when ISE issues a certificate to an endpoint during onboarding (via SCEP), the Common Name (CN) field of the certificate is automatically populated with the endpoint's hostname. This allows ISE to identify and authorize the device in…
Question
What should be considered when configuring certificates for BYOD?
Options
- AAn endpoint certificate is mandatory for the Cisco ISE BYOD
- BAn Android endpoint uses EST whereas other operation systems use SCEP for enrollment
- CThe CN field is populated with the endpoint host name.
- DThe SAN field is populated with the end user name
How the community answered
(58 responses)- A3% (2)
- B2% (1)
- C93% (54)
- D2% (1)
Explanation
In Cisco ISE BYOD certificate provisioning, when ISE issues a certificate to an endpoint during onboarding (via SCEP), the Common Name (CN) field of the certificate is automatically populated with the endpoint's hostname. This allows ISE to identify and authorize the device in subsequent authentications. Option A is incorrect - an endpoint certificate is not mandatory for all BYOD flows; some use username/password. Option B is incorrect - Android uses SCEP (Simple Certificate Enrollment Protocol) just like other platforms; EST (Enrollment over Secure Transport) is not what Android uses by default in ISE BYOD. Option D is incorrect - the SAN (Subject Alternative Name) field is not populated with the end user's name by default; the user identity is typically captured in the CN or a separate field, and the SAN is used for DNS names or email addresses, not the end user name in this context.
Topics
Community Discussion
No community discussion yet for this question.