300-715 · Question #195
A network administrator is currently using Cisco ISE to authenticate devices and users via 802.1X. There is now a need to also authorize devices and users using EAP-TLS. Which two additional…
The correct answer is D. Certificate Authentication Profile E. EAP Authorization Profile. EAP-TLS is a certificate-based authentication method. To support it in Cisco ISE beyond standard 802.1X, two additional components are required. First, a Certificate Authentication Profile (D) must be created to tell ISE how to validate client certificates and which certificate…
Question
A network administrator is currently using Cisco ISE to authenticate devices and users via 802.1X. There is now a need to also authorize devices and users using EAP-TLS. Which two additional components must be configured in Cisco ISE to accomplish this? (Choose two.)
Options
- ANetwork Device Group
- BSerial Number attribute that maps to a CA Server
- CCommon Name attribute that maps to an identity store
- DCertificate Authentication Profile
- EEAP Authorization Profile
How the community answered
(31 responses)- A6% (2)
- B13% (4)
- C3% (1)
- D77% (24)
Explanation
EAP-TLS is a certificate-based authentication method. To support it in Cisco ISE beyond standard 802.1X, two additional components are required. First, a Certificate Authentication Profile (D) must be created to tell ISE how to validate client certificates and which certificate field (e.g., Subject Alternative Name or CN) to use when looking up the identity in a store. Second, an EAP Authorization Profile (E) must be configured to define the authorization result granted to successfully authenticated EAP-TLS clients. Option A (Network Device Group) is used for device segmentation, not certificate auth. Option B references a CA Server mapping by serial number, which is not a standard ISE component name. Option C describes an attribute mapping that is configured within a Certificate Authentication Profile, not as a standalone component.
Topics
Community Discussion
No community discussion yet for this question.