300-715 · Question #2
When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?
The correct answer is D. SID. Cisco ISE uses the Security Identifier (SID) to uniquely identify and resolve ambiguous Active Directory group names.
Question
When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?
Options
- AMIB
- BTGT
- COMAB
- DSID
How the community answered
(27 responses)- B4% (1)
- C7% (2)
- D89% (24)
Why each option
Cisco ISE uses the Security Identifier (SID) to uniquely identify and resolve ambiguous Active Directory group names.
MIB (Management Information Base) is used in SNMP for network device management, not for resolving Active Directory group names.
TGT (Ticket Granting Ticket) is part of the Kerberos authentication process, used to obtain service tickets, not to resolve group names directly.
OMAB is not a standard acronym related to Active Directory group resolution.
Cisco ISE relies on the Security Identifier (SID) attribute from Active Directory to uniquely identify groups and resolve potential ambiguity when multiple groups might share the same name in different domains or sub-domains. SIDs ensure that each security principal, including groups, has a distinct and immutable identifier within the Windows security model.
Concept tested: Cisco ISE Active Directory group resolution using SID
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_guide_31/b_ISE_admin_guide_31_chapter_01000.html#concept_50170A5825E14917BE1B6C4F37386D22
Topics
Community Discussion
No community discussion yet for this question.