300-715 · Question #174
An engineer builds a five-node distributed Cisco ISE deployment. The first two deployed nodes are responsible for the primary and secondary administration and monitoring personas. Which persona…
The correct answer is B. Cisco ISE Role SECONDARY configuration with Administration disabled, Monitoring enabled, Policy Service enabled with Session Services, Profiling Service, and Passive Identity Service. For the remaining three Cisco ISE nodes to exclusively handle RADIUS/TACACS+ authentication, identity lookups, and policy evaluation as dedicated PSNs, they need to be configured with the Policy Service enabled, including Session Services, Profiling Service, and the Passive…
Question
An engineer builds a five-node distributed Cisco ISE deployment. The first two deployed nodes are responsible for the primary and secondary administration and monitoring personas. Which persona configuration is necessary to have the remaining three Cisco ISE nodes serve as dedicated nodes in the Cisco ISE cube that is responsible only for handling the RADIUS and TACACS+ authentication requests, identity lookups, and policy evaluation? A. B. C. D.
Exhibits
Options
- ACisco ISE Role SECONDARY configuration with Administration disabled, Monitoring enabled, Policy Service enabled with Session Services, Profiling Service, and Device Admin Service.
- BCisco ISE Role SECONDARY configuration with Administration disabled, Monitoring enabled, Policy Service enabled with Session Services, Profiling Service, and Passive Identity Service.
- CCisco ISE Role SECONDARY configuration with Administration disabled, Monitoring enabled, Policy Service enabled with Session Services, Profiling Service, and Threat Centric NAC Service.
- DCisco ISE Role SECONDARY configuration with Administration disabled, Monitoring enabled, Policy Service enabled with Session Services and Profiling Service.
How the community answered
(33 responses)- A3% (1)
- B88% (29)
- C6% (2)
- D3% (1)
Why each option
For the remaining three Cisco ISE nodes to exclusively handle RADIUS/TACACS+ authentication, identity lookups, and policy evaluation as dedicated PSNs, they need to be configured with the Policy Service enabled, including Session Services, Profiling Service, and the Passive Identity Service.
While Device Admin Service handles TACACS+ device administration, the explicit mention of 'identity lookups' in the requirements makes Passive Identity Service a more direct and essential inclusion, and Session Services generally covers general TACACS+ authentication.
The Policy Service Persona (PSN) is responsible for handling network access requests (RADIUS and TACACS+ authentication via Session Services), policy evaluation, and profiling (via Profiling Service). Enabling the Passive Identity Service specifically addresses the requirement for 'identity lookups,' which collects identity data from sources like Active Directory without requiring active probing.
Threat Centric NAC Service is not explicitly mentioned as a required function for these dedicated nodes responsible for authentication, identity lookups, and policy evaluation.
This option only includes Session Services and Profiling Service, omitting the critical Passive Identity Service required for explicit 'identity lookups' mentioned in the question.
Concept tested: Cisco ISE Distributed Deployment Personas
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_guide_30/b_ise_admin_guide_30_chapter_01000.html#concept_AD3F4B5421734362846DF7BF003C647D
Topics
Community Discussion
No community discussion yet for this question.



