nerdexam
Cisco

300-715 · Question #236

An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal. Which condition must be used when…

The correct answer is A. Endpoint Identity Group is Blocklist, and the BYOD state is Registered. To block access for stolen BYOD endpoints onboarded without a certificate, an authorization policy should check if the Endpoint Identity Group is 'Blocklist' and the BYOD state is 'Registered'.

BYOD

Question

An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal. Which condition must be used when configuring an authorization policy that sets DenyAccess permission?

Options

  • AEndpoint Identity Group is Blocklist, and the BYOD state is Registered.
  • BEndpoint Identify Group is Blocklist, and the BYOD state is Pending.
  • CEndpoint Identity Group is Blocklist, and the BYOD state is Lost.
  • DEndpoint Identity Group is Blocklist, and the BYOD state is Reinstate.

How the community answered

(55 responses)
  • A
    80% (44)
  • B
    11% (6)
  • C
    7% (4)
  • D
    2% (1)

Why each option

To block access for stolen BYOD endpoints onboarded without a certificate, an authorization policy should check if the Endpoint Identity Group is 'Blocklist' and the BYOD state is 'Registered'.

AEndpoint Identity Group is Blocklist, and the BYOD state is Registered.Correct

When a device is reported as stolen in the My Devices portal, Cisco ISE automatically moves it into the 'Blocklist' Endpoint Identity Group. For devices successfully onboarded, their BYOD state remains 'Registered', even if stolen, indicating they previously completed the registration process. Combining these two conditions in an authorization policy accurately targets and denies access to such devices.

BEndpoint Identify Group is Blocklist, and the BYOD state is Pending.

A 'Pending' BYOD state indicates a device is still in the process of registration, not yet fully onboarded and then reported stolen.

CEndpoint Identity Group is Blocklist, and the BYOD state is Lost.

'Lost' is not a standard BYOD state attribute used in authorization policies for devices marked as stolen; 'Blocklist' is the primary identity group assignment for such cases.

DEndpoint Identity Group is Blocklist, and the BYOD state is Reinstate.

'Reinstate' is a state indicating a device is being brought back into compliance or re-onboarded, not a state for a stolen device requiring denial of access.

Concept tested: Cisco ISE BYOD authorization policy for stolen devices

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_chapter_0110.html

Topics

#BYOD onboarding#Authorization policy#Endpoint identity groups#My Devices Portal

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice