nerdexam
Cisco

300-715 · Question #244

An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not…

The correct answer is C. Verify that the profiling service is running on the new PSN. If a new Policy Service Node (PSN) in Cisco ISE is not correctly profiling endpoints, the profiling service on that specific PSN must be verified and enabled. Profiling is essential for assigning accurate attributes and matching endpoints to the correct authorization policies.

Profiler

Question

An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not hitting the correct policies. This was working correctly on the previous PSN. Which action must be taken to ensure the endpoints get identified?

Options

  • AVerify that the MnT node is tracking the session.
  • BVerify the shared secret used between the switch and the PSN.
  • CVerify that the profiling service is running on the new PSN.
  • DVerify that the authentication request the PSN is receiving is not malformed.

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    8% (5)
  • C
    70% (42)
  • D
    18% (11)

Why each option

If a new Policy Service Node (PSN) in Cisco ISE is not correctly profiling endpoints, the profiling service on that specific PSN must be verified and enabled. Profiling is essential for assigning accurate attributes and matching endpoints to the correct authorization policies.

AVerify that the MnT node is tracking the session.

Verifying the MnT node tracks the session is important for monitoring but doesn't directly solve the issue of the PSN failing to profile endpoints correctly.

BVerify the shared secret used between the switch and the PSN.

If the shared secret between the switch and PSN were incorrect, authentication itself would likely fail, not just profiling. The question states endpoints authenticate, but get wrong profiles.

CVerify that the profiling service is running on the new PSN.Correct

Profiling services are responsible for collecting endpoint attributes and determining their type, which is critical for assigning the correct policies. When a PSN is replaced, the profiling service may not be enabled by default or could be in a stopped state, leading to endpoints not getting the right profiles.

DVerify that the authentication request the PSN is receiving is not malformed.

A malformed authentication request would likely cause authentication failure, not just incorrect profiling after successful authentication.

Concept tested: Cisco ISE PSN persona - Profiling Service

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html#concept_208082520F3E481D886ED12BE7957788

Topics

#Cisco ISE#Profiling Service#PSN#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice