nerdexam
CiscoCisco

300-715 · Question #224

300-715 Question #224: Real Exam Question with Answer & Explanation

The correct answer is C: Use the authorization policy within the policy set to group each AD group with their respective. To apply different posture conditions based on Active Directory groups, the authorization policy within a policy set should be configured to map each AD group to its respective posture requirement.

Policy Enforcement

Question

An engineer is configuring a posture policy for Windows 10 endpoints and wants to ensure that users in each AD group have different conditions to meet to be compliant. What must be done to accomplish this task?

Options

  • Aidentify The users groups needed for different policies and create service conditions to map
  • BConfigure a simple condition for each AD group and use it in the posture policy for each use
  • CUse the authorization policy within the policy set to group each AD group with their respective
  • DChange the posture requirements to use an AD group for each use case then use those

Explanation

To apply different posture conditions based on Active Directory groups, the authorization policy within a policy set should be configured to map each AD group to its respective posture requirement.

Common mistakes.

  • A. While identifying user groups is a first step, 'service conditions to map' is not the specific mechanism; authorization policies are used to link AD groups to posture requirements.

Concept tested. Cisco ISE posture policy integration with authorization policies

Reference. https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ISE_admin_guide_27/b_ISE_admin_guide_27_chapter_010.html#concept_407817D5D72647788481A051876D02A9

Topics

#Cisco ISE#Posture Policy#Authorization Policy#Active Directory Integration

Community Discussion

No community discussion yet for this question.

Full 300-715 PracticeBrowse All 300-715 Questions