300-715 · Question #184
Which two external identity stores support EAP-TLS and PEAP-TLS? (Choose two.)
The correct answer is A. Active Directory E. LDAP. EAP-TLS and PEAP-TLS are certificate-based authentication methods. For ISE to validate a client certificate against an external identity store, that store must support binary certificate comparison or certificate retrieval. Active Directory (AD) supports binary attribute…
Question
Which two external identity stores support EAP-TLS and PEAP-TLS? (Choose two.)
Options
- AActive Directory
- BRADIUS Token
- CInternal Database
- DRSA SecurlD
- ELDAP
How the community answered
(37 responses)- A92% (34)
- C3% (1)
- D5% (2)
Explanation
EAP-TLS and PEAP-TLS are certificate-based authentication methods. For ISE to validate a client certificate against an external identity store, that store must support binary certificate comparison or certificate retrieval. Active Directory (AD) supports binary attribute comparison (userCertificate attribute) and is a primary external identity source for certificate-based EAP in ISE. LDAP also supports binary certificate comparison, making it a valid external store for EAP-TLS and PEAP-TLS. RADIUS Token servers and RSA SecurID are designed for one-time password (OTP) authentication and do not support certificate-based EAP methods. The question specifically asks for external identity stores, which excludes the ISE Internal Database (option C), even though it also supports certificate-based EAP.
Topics
Community Discussion
No community discussion yet for this question.