nerdexam
Cisco

300-715 · Question #243

An engineer needs to configure a Cisco ISE server to issue a CoA for endpoints already authenticated to access the network. The CoA option must be enforced on a session, even if there are multiple act

The correct answer is A. the Reauth CoA option in the Cisco ISE system profiling settings enabled. To ensure a Change of Authorization (CoA) is enforced on a specific session even when multiple sessions are active on a port, the Reauth CoA option must be enabled in Cisco ISE's system profiling settings. This allows ISE to initiate a re-authentication for the individual session

Policy Enforcement

Question

An engineer needs to configure a Cisco ISE server to issue a CoA for endpoints already authenticated to access the network. The CoA option must be enforced on a session, even if there are multiple active sessions on a port. What must be configured to accomplish this task?

Options

  • Athe Reauth CoA option in the Cisco ISE system profiling settings enabled
  • Ban endpoint profiling policy with the No CoA option enabled
  • Can endpoint profiling policy with the Port Bounce CoA option enabled
  • Dthe Port Bounce CoA option in the Cisco ISE system profiling settings enabled

How the community answered

(32 responses)
  • A
    78% (25)
  • B
    13% (4)
  • C
    6% (2)
  • D
    3% (1)

Why each option

To ensure a Change of Authorization (CoA) is enforced on a specific session even when multiple sessions are active on a port, the Reauth CoA option must be enabled in Cisco ISE's system profiling settings. This allows ISE to initiate a re-authentication for the individual session without affecting others.

Athe Reauth CoA option in the Cisco ISE system profiling settings enabledCorrect

The "Reauth CoA" option in Cisco ISE is designed to send a CoA-Reauthenticate message to the network access device (NAD), which then triggers a re-authentication for a specific session. This is crucial for environments with multi-auth ports, as it avoids disconnecting other active sessions on the same port, ensuring only the target session is re-evaluated.

Ban endpoint profiling policy with the No CoA option enabled

An endpoint profiling policy with "No CoA" enabled would prevent any CoA from being sent, which is contrary to the goal.

Can endpoint profiling policy with the Port Bounce CoA option enabled

"Port Bounce CoA" is an action that disconnects and then immediately brings up the entire port, affecting all sessions, not just a specific one.

Dthe Port Bounce CoA option in the Cisco ISE system profiling settings enabled

Configuring "Port Bounce CoA" in the system settings would apply a port bounce to all CoA actions, which would affect all sessions on a port, not just the target session, which is not what the question implies by "enforced on a session".

Concept tested: Cisco ISE CoA options - Reauth CoA vs Port Bounce

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html#concept_902D82D3E5664CD8A8504B76A188C0A9

Topics

#Change of Authorization (CoA)#Reauth CoA#Dynamic Authorization#Session Management

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice