300-715 · Question #232
An administrator is configuring the Native Supplicant Profile to be used with the Cisco ISE posture agents and needs to test the connection using wired devices to determine which profile settings…
The correct answer is C. certificate template E. allowed protocol. To test Native Supplicant Profile settings for wired devices with Cisco ISE posture agents, the administrator should configure the certificate template and allowed protocol options.
Question
An administrator is configuring the Native Supplicant Profile to be used with the Cisco ISE posture agents and needs to test the connection using wired devices to determine which profile settings are available. Which two configuration settings should be used to accomplish this task? (Choose two.)
Options
- Aauthentication mode
- Bproxy host/IP
- Ccertificate template
- Dsecurity
- Eallowed protocol
How the community answered
(32 responses)- A3% (1)
- B19% (6)
- C72% (23)
- D6% (2)
Why each option
To test Native Supplicant Profile settings for wired devices with Cisco ISE posture agents, the administrator should configure the certificate template and allowed protocol options.
Authentication mode (e.g., user, machine) is a supplicant setting, but the certificate template and allowed protocol are more foundational for establishing a secure connection in the context of testing profile settings.
Proxy host/IP is relevant for agent communication through a proxy but is not a core Native Supplicant Profile setting that determines initial wired connection success.
The certificate template is a critical setting as it dictates how the native supplicant obtains and presents its identity certificate for secure EAP-TLS or other certificate-based authentication methods, which is fundamental for wired connection security.
"Security" is a broad term, and specific settings like certificate templates and allowed protocols define the security posture more precisely than a general category.
The allowed protocol setting specifies the Extensible Authentication Protocol (EAP) types (e.g., EAP-TLS, PEAP) that the supplicant can use for authentication, directly impacting the ability of wired devices to establish a connection with Cisco ISE.
Concept tested: Cisco ISE Native Supplicant Profile configuration
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_chapter_0110.html#concept_E227284F45C14620A80C5089E4F7D37D
Topics
Community Discussion
No community discussion yet for this question.