nerdexam
Cisco

300-715 · Question #119

An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it…

The correct answer is C. Create an SCEP profile to link Cisco ISE with the root certificate authority. To enable Cisco ISE to issue certificates from an existing Certificate Authority for BYOD devices, a SCEP profile must be configured within ISE.

BYOD

Question

An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE. What must be configured within Cisco ISE to accomplish this goal?

Options

  • ACreate a certificate signing request and have the root certificate authority sign it.
  • BAdd the root certificate authority to the trust store and enable it for authentication.
  • CCreate an SCEP profile to link Cisco ISE with the root certificate authority.
  • DAdd an OCSP profile and configure the root certificate authority as secondary.

How the community answered

(59 responses)
  • A
    3% (2)
  • B
    8% (5)
  • C
    71% (42)
  • D
    17% (10)

Why each option

To enable Cisco ISE to issue certificates from an existing Certificate Authority for BYOD devices, a SCEP profile must be configured within ISE.

ACreate a certificate signing request and have the root certificate authority sign it.

Creating a CSR in ISE and having the root CA sign it would establish ISE as an intermediate CA, but it would not enable ISE to issue certificates from the existing CA for individual BYOD endpoints through a proxy-like mechanism.

BAdd the root certificate authority to the trust store and enable it for authentication.

Adding the root CA to the trust store and enabling it for authentication is crucial for ISE to trust certificates issued by that CA, but it does not enable ISE to request and issue new certificates on behalf of BYOD devices.

CCreate an SCEP profile to link Cisco ISE with the root certificate authority.Correct

SCEP (Simple Certificate Enrollment Protocol) allows devices to obtain certificates from a CA using an HTTP-based communication. By configuring a SCEP profile in Cisco ISE, it acts as a proxy, facilitating certificate enrollment requests from BYOD endpoints to the external Certificate Authority (CA), thereby issuing certificates without replacing the existing CA infrastructure.

DAdd an OCSP profile and configure the root certificate authority as secondary.

An OCSP (Online Certificate Status Protocol) profile is used for certificate revocation checking, not for issuing new certificates or linking ISE to a CA for enrollment purposes.

Concept tested: Cisco ISE BYOD SCEP certificate enrollment

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html#concept_E7764A9B8017409292BA4E913C363404

Topics

#BYOD#Certificate Management#SCEP#External CA Integration

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice