nerdexam
Cisco

300-715 · Question #2

When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?

The correct answer is D. SID. Cisco ISE uses the Security Identifier (SID) to uniquely identify and resolve ambiguous Active Directory group names.

Policy Enforcement

Question

When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?

Options

  • AMIB
  • BTGT
  • COMAB
  • DSID

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    7% (2)
  • D
    89% (24)

Why each option

Cisco ISE uses the Security Identifier (SID) to uniquely identify and resolve ambiguous Active Directory group names.

AMIB

MIB (Management Information Base) is used in SNMP for network device management, not for resolving Active Directory group names.

BTGT

TGT (Ticket Granting Ticket) is part of the Kerberos authentication process, used to obtain service tickets, not to resolve group names directly.

COMAB

OMAB is not a standard acronym related to Active Directory group resolution.

DSIDCorrect

Cisco ISE relies on the Security Identifier (SID) attribute from Active Directory to uniquely identify groups and resolve potential ambiguity when multiple groups might share the same name in different domains or sub-domains. SIDs ensure that each security principal, including groups, has a distinct and immutable identifier within the Windows security model.

Concept tested: Cisco ISE Active Directory group resolution using SID

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_guide_31/b_ISE_admin_guide_31_chapter_01000.html#concept_50170A5825E14917BE1B6C4F37386D22

Topics

#Active Directory Integration#Group Resolution#Security Identifier#Cisco ISE

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice