300-715 · Question #118
There is a need within an organization for a new policy to be created in Cisco ISE. It must validate that a specific anti-virus application is not only installed, but running on a machine before it…
The correct answer is C. application. To validate that a specific anti-virus application is both installed and actively running on a machine for network access, the administrator should configure an application posture condition in Cisco ISE.
Question
There is a need within an organization for a new policy to be created in Cisco ISE. It must validate that a specific anti-virus application is not only installed, but running on a machine before it is allowed access to the network. Which posture condition should the administrator configure in order for this policy to work?
Options
- Afile
- Bregistry
- Capplication
- Dservice
How the community answered
(28 responses)- A4% (1)
- C89% (25)
- D7% (2)
Why each option
To validate that a specific anti-virus application is both installed and actively running on a machine for network access, the administrator should configure an application posture condition in Cisco ISE.
A file posture condition checks for the presence or content of specific files, not the running state of an application.
A registry posture condition checks for specific registry key values, which might indicate installation but not necessarily the running state of an application.
An application posture condition in Cisco ISE is specifically designed to check for the presence, version, and running state of installed applications, such as antivirus software. This condition allows the administrator to verify that the required antivirus application is not only installed but also actively running on the endpoint before granting network access.
A service posture condition checks for the presence and running state of operating system services, but a standalone anti-virus program is typically identified and managed as an 'application' within ISE's posture module, even if it runs services, providing a more direct and comprehensive check for the AV software itself.
Concept tested: Cisco ISE Posture - Application Condition
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html#task_D102A8C16259441D91E5B5FC225F883B
Topics
Community Discussion
No community discussion yet for this question.