nerdexam
Cisco

300-715 · Question #118

There is a need within an organization for a new policy to be created in Cisco ISE. It must validate that a specific anti-virus application is not only installed, but running on a machine before it…

The correct answer is C. application. To validate that a specific anti-virus application is both installed and actively running on a machine for network access, the administrator should configure an application posture condition in Cisco ISE.

Endpoint Compliance

Question

There is a need within an organization for a new policy to be created in Cisco ISE. It must validate that a specific anti-virus application is not only installed, but running on a machine before it is allowed access to the network. Which posture condition should the administrator configure in order for this policy to work?

Options

  • Afile
  • Bregistry
  • Capplication
  • Dservice

How the community answered

(28 responses)
  • A
    4% (1)
  • C
    89% (25)
  • D
    7% (2)

Why each option

To validate that a specific anti-virus application is both installed and actively running on a machine for network access, the administrator should configure an application posture condition in Cisco ISE.

Afile

A file posture condition checks for the presence or content of specific files, not the running state of an application.

Bregistry

A registry posture condition checks for specific registry key values, which might indicate installation but not necessarily the running state of an application.

CapplicationCorrect

An application posture condition in Cisco ISE is specifically designed to check for the presence, version, and running state of installed applications, such as antivirus software. This condition allows the administrator to verify that the required antivirus application is not only installed but also actively running on the endpoint before granting network access.

Dservice

A service posture condition checks for the presence and running state of operating system services, but a standalone anti-virus program is typically identified and managed as an 'application' within ISE's posture module, even if it runs services, providing a more direct and comprehensive check for the AV software itself.

Concept tested: Cisco ISE Posture - Application Condition

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_3_0/b_ise_admin_guide_30_chapter_0100.html#task_D102A8C16259441D91E5B5FC225F883B

Topics

#Cisco ISE#Posture Policy#Application Condition#Endpoint Compliance

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice