300-715 · Question #255
An engineer is using profiling to determine what access an endpoint must receive. After configuring both Cisco ISE and the network devices for 802.1X and profiling, the endpoints do not profile prior
The correct answer is A. Closed mode is restricting the collection of the attributes prior to authentication. E. The switch is collecting the attributes via RADIUS but the probes are not sending them.. Endpoints are not profiling prior to authentication despite 802.1X and profiling configuration, likely because closed mode restricts attribute collection and/or probes are not sending attributes collected by the switch via RADIUS.
Question
An engineer is using profiling to determine what access an endpoint must receive. After configuring both Cisco ISE and the network devices for 802.1X and profiling, the endpoints do not profile prior to authentication. What are two reasons this is happening? (Choose two.)
Options
- AClosed mode is restricting the collection of the attributes prior to authentication.
- BThe HTTP probe is malfunctioning due to closed mode being enabled.
- CThe SNMP probe is not enabled.
- DNetFlow is not enable on the switch, so the attributes will not be collected.
- EThe switch is collecting the attributes via RADIUS but the probes are not sending them.
How the community answered
(14 responses)- A71% (10)
- B7% (1)
- C7% (1)
- D14% (2)
Why each option
Endpoints are not profiling prior to authentication despite 802.1X and profiling configuration, likely because closed mode restricts attribute collection and/or probes are not sending attributes collected by the switch via RADIUS.
In Cisco ISE's closed mode, network access is denied by default until an endpoint successfully authenticates, which inherently limits the ability to collect detailed profiling attributes before authentication occurs. This restriction means profiling data collection for policy enforcement often happens post-authentication in closed mode.
While HTTP probes are used for profiling, closed mode itself doesn't directly cause a probe malfunction; rather, closed mode prevents the endpoint from fully connecting, which can impede any probe requiring network access before authentication.
SNMP probes are one type of profiling probe, but not having it enabled is only one possible reason for profiling failure, and the question asks for two reasons, implying other mechanisms might also be at play or failing.
NetFlow is a common profiling probe, but it's not the only method for attribute collection. Even if NetFlow is not enabled, other probes like RADIUS or DHCP could still be collecting attributes.
The switch might be configured to collect profiling attributes, such as those gathered via RADIUS, but if the configured Cisco ISE probes are not enabled or correctly configured to receive and process these attributes, the profiling service will not receive the data to build an endpoint profile. This prevents the endpoint from being profiled effectively.
Concept tested: Cisco ISE pre-authentication profiling challenges
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01101.html#concept_81F786B6D12D420F921B52F2E23E6C2D
Topics
Community Discussion
No community discussion yet for this question.