300-715 · Question #116
Refer to the exhibit. An organization recently implemented network device administration using Cisco ISE. Upon testing the ability to access all of the required devices, a user in the Cisco ISE…
The correct answer is D. The authorization policy doesn't correctly grant them access to the finance devices. The user from the IT Admins group cannot log in to a finance department device because the authorization policy in Cisco ISE is not correctly configured to grant them the necessary access.
Question
Refer to the exhibit. An organization recently implemented network device administration using Cisco ISE. Upon testing the ability to access all of the required devices, a user in the Cisco ISE group IT Admins is attempting to login to a device in their organization's finance department but is unable to. What is the problem?
Exhibit
Options
- AThe IT training rule is taking precedence over the IT Admins rule.
- BThe authorization conditions wrongly allow IT Admins group no access to finance devices.
- CThe finance location is not a condition in the policy set.
- DThe authorization policy doesn't correctly grant them access to the finance devices.
How the community answered
(32 responses)- A6% (2)
- B9% (3)
- C3% (1)
- D81% (26)
Why each option
The user from the IT Admins group cannot log in to a finance department device because the authorization policy in Cisco ISE is not correctly configured to grant them the necessary access.
While a higher-precedence rule *could* cause this, the overarching problem is that the policy as a whole 'doesn't correctly grant them access,' which encompasses specific rule ordering or content issues.
This choice states the conditions wrongly allow no access, which implies a misconfiguration but doesn't fully encompass the broader problem that the 'policy doesn't correctly grant access,' which could be a missing rule or incorrect permission.
If the finance location is not a condition, it means the policy cannot differentiate access based on that specific location; however, this is a symptom of the authorization policy not being correctly configured to grant access, rather than the ultimate problem itself.
The problem lies with the authorization policy not correctly granting IT Admins access to finance devices. If no rule matches or a lower-priority rule with restrictive permissions is matched due to incorrect policy design or ordering, access would be denied, indicating the policy is incorrectly designed or ordered for the desired access.
Concept tested: Cisco ISE Device Administration - Authorization Policy Evaluation
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html#task_4FE3226D131F467C920D45B07E92A281
Topics
Community Discussion
No community discussion yet for this question.
