300-715 · Question #130
Which three conditions can be used for posture checking? (Choose three.)
The correct answer is C. file D. application E. services. Posture checking can evaluate an endpoint's compliance based on the presence of specific files, running applications, and active services.
Question
Which three conditions can be used for posture checking? (Choose three.)
Options
- Acertificate
- Boperating system
- Cfile
- Dapplication
- Eservices
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C92% (34)
Why each option
Posture checking can evaluate an endpoint's compliance based on the presence of specific files, running applications, and active services.
While certificates are used for identity and can influence posture, 'certificate' itself is not a dynamic condition that a posture agent checks in the same way as file, application, or service status.
Operating system type and version are typically attributes used for policy matching in authentication or authorization, but not directly a posture condition that an agent dynamically assesses for security state.
File condition checks verify the existence, version, date, or content of specific files on an endpoint, ensuring critical system files or required application files are present and up-to-date for compliance.
Application condition checks determine if specific applications are installed or running on the endpoint, allowing enforcement of policies that require or prohibit certain software for security purposes.
Services condition checks examine the status of system services (e.g., firewall service, antivirus service) on an endpoint, ensuring essential security services are active and properly configured.
Concept tested: Cisco ISE posture conditions
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0100.html#concept_AC4E8D775EF84B918231CE3D92182D20
Topics
Community Discussion
No community discussion yet for this question.