300-715 · Question #197
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for 1 day. When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete…
The correct answer is C. The Endpoint Purge Policy is set to 30 days for guest devices. The problem of guest endpoints retaining access beyond one day, despite an intended one-day validity, is caused by the Endpoint Purge Policy being set to 30 days for guest devices. This policy dictates when endpoint entries are removed from the identity store, distinct from…
Question
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for 1 day. When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
Options
- AThe RADIUS policy set for guest access is set to allow repeated authentication of the same
- BThe length of access is set to 7 days in the Guest Portal Settings.
- CThe Endpoint Purge Policy is set to 30 days for guest devices.
- DThe Guest Account Purge Policy is set to 15 days.
How the community answered
(50 responses)- A10% (5)
- B6% (3)
- C82% (41)
- D2% (1)
Why each option
The problem of guest endpoints retaining access beyond one day, despite an intended one-day validity, is caused by the Endpoint Purge Policy being set to 30 days for guest devices. This policy dictates when endpoint entries are removed from the identity store, distinct from guest account validity.
A RADIUS policy allowing repeated authentication does not explain why an endpoint remains registered and grants access beyond its intended validity period, as the core issue is the endpoint itself not being purged.
If the length of access in Guest Portal Settings was set to 7 days, it would directly extend access, but the problem description implies an intended 1-day validity is being bypassed because the endpoint is not deleted, pointing to a purge policy.
The Endpoint Purge Policy in Cisco ISE dictates when endpoint entries, including those of guest devices, are removed from the identity store. If this policy is set to 30 days for guest devices, even if a guest account's validity is 1 day, the endpoint registration itself will persist for 30 days, potentially allowing the device to re-authenticate or be recognized even after the initial guest account expires.
The Guest Account Purge Policy controls when the guest user accounts are deleted from ISE, not the associated endpoint registrations in the Guest Endpoints identity store. A guest account might be purged, but if the endpoint is not, it could still be recognized.
Concept tested: Cisco ISE Endpoint Purge Policy
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_01004.html
Topics
Community Discussion
No community discussion yet for this question.