nerdexam
Cisco

300-715 · Question #113

A company is attempting to improve their BYOD policies and restrict access based on certain criteria. The company's subnets are organized by building. Which attribute should be used in order to gain a

The correct answer is B. IP address. To restrict access based on location where subnets are organized by building, the IP address attribute should be utilized in Cisco ISE policies.

BYOD

Question

A company is attempting to improve their BYOD policies and restrict access based on certain criteria. The company's subnets are organized by building. Which attribute should be used in order to gain access based on location?

Options

  • Astatic group assignment
  • BIP address
  • Cdevice registration status
  • DMAC address

How the community answered

(53 responses)
  • A
    6% (3)
  • B
    79% (42)
  • C
    4% (2)
  • D
    11% (6)

Why each option

To restrict access based on location where subnets are organized by building, the IP address attribute should be utilized in Cisco ISE policies.

Astatic group assignment

Static group assignment is a method for grouping devices or users but does not inherently provide location information based on network topology.

BIP addressCorrect

The IP address is the most direct and effective attribute to use for location-based access control when subnets are organized by building. Since each building corresponds to a specific subnet, policies can be crafted to allow or deny access based on the endpoint's assigned IP address range, directly reflecting its physical location.

Cdevice registration status

Device registration status indicates whether a device is registered with ISE but does not provide details about its current network location.

DMAC address

A MAC address uniquely identifies a device but does not inherently provide information about its current network location without additional mapping to the network infrastructure.

Concept tested: Cisco ISE Policy - Location-based Access Control

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html

Topics

#BYOD policies#Location-based access#Access control#Identity groups

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice