nerdexam
Cisco

300-715 · Question #114

An engineer is migrating users from MAB to 802.1X on the network. This must be done during normal business hours with minimal impact to users. Which CoA method should be used?

The correct answer is D. Session Reauthentication. To smoothly migrate users from MAB to 802.1X during normal business hours with minimal impact, the Session Reauthentication Change of Authorization (CoA) method should be employed.

Policy Enforcement

Question

An engineer is migrating users from MAB to 802.1X on the network. This must be done during normal business hours with minimal impact to users. Which CoA method should be used?

Options

  • APort Bounce
  • BPort Shutdown
  • CSession Termination
  • DSession Reauthentication

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    14% (6)
  • D
    76% (32)

Why each option

To smoothly migrate users from MAB to 802.1X during normal business hours with minimal impact, the Session Reauthentication Change of Authorization (CoA) method should be employed.

APort Bounce

Port Bounce (Port Reset) physically resets the switch port, causing a momentary loss of link and disrupting any active user sessions.

BPort Shutdown

Port Shutdown disables the switch port entirely, which would completely disconnect the user and require manual intervention or the user to unplug and re-plug.

CSession Termination

Session Termination immediately drops the current network session, which is disruptive, although less so than a port bounce, but Session Reauthentication offers a smoother transition.

DSession ReauthenticationCorrect

Session Reauthentication (CoA) is the most appropriate method because it forces the endpoint to reauthenticate without dropping the network connection entirely or resetting the physical port. This allows the network access device to re-evaluate the authentication policy, moving the endpoint from MAB to 802.1X if configured, with minimal disruption to the user's ongoing network session.

Concept tested: Cisco ISE Change of Authorization (CoA) - Reauthentication

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html#concept_3500D00276DD4E25B124C27EDD9541F7

Topics

#Change of Authorization#802.1X migration#Authentication methods#Minimal user impact

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice