300-715 · Question #212
Which compliance status is set when a matching posture policy has been defined for that endpoint, but all the mandatory requirements during posture assessment are not met?
The correct answer is C. non-compliant. When an endpoint is assessed against a defined posture policy but fails to meet its mandatory requirements, its compliance status is set to 'non-compliant'.
Question
Which compliance status is set when a matching posture policy has been defined for that endpoint, but all the mandatory requirements during posture assessment are not met?
Options
- Aunauthorized
- Buntrusted
- Cnon-compliant
- Dunknown
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- C94% (33)
Why each option
When an endpoint is assessed against a defined posture policy but fails to meet its mandatory requirements, its compliance status is set to 'non-compliant'.
Unauthorized typically refers to a failure in authentication or an explicit denial of network access, rather than a specific posture compliance status.
Untrusted is a general classification that may be assigned based on various factors, but 'non-compliant' is the specific status for failed posture.
In Cisco ISE posture assessment, if a posture policy is defined for an endpoint and that endpoint is evaluated but fails to satisfy all mandatory requirements specified in the policy, its compliance status is designated as 'non-compliant'.
Unknown is the status assigned when an endpoint's posture cannot be assessed, or its status has not yet been determined, not when it explicitly fails compliance.
Concept tested: Cisco ISE posture compliance status
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0121.html
Topics
Community Discussion
No community discussion yet for this question.