nerdexam
Cisco

300-715 · Question #258

The security team wants to secure the wired network. A legacy printer on the network with the MAC address 00:43:08:50:64:60 does not support 802.1X. Which setting must be enabled in the Allowed…

The correct answer is D. Process Host Lookup. To enable MAC Authentication Bypass (MAB) for non-802.1X devices like legacy printers in Cisco ISE, the "Process Host Lookup" setting must be enabled in the Authentication Policy.

Policy Enforcement

Question

The security team wants to secure the wired network. A legacy printer on the network with the MAC address 00:43:08:50:64:60 does not support 802.1X. Which setting must be enabled in the Allowed Authentication Protocols list in your Authentication Policy for Cisco ISE to support MAB for this MAC address?

Options

  • AMS-CHAPv2
  • BEAP-TLS
  • CPAP
  • DProcess Host Lookup

How the community answered

(21 responses)
  • B
    5% (1)
  • D
    95% (20)

Why each option

To enable MAC Authentication Bypass (MAB) for non-802.1X devices like legacy printers in Cisco ISE, the "Process Host Lookup" setting must be enabled in the Authentication Policy.

AMS-CHAPv2

MS-CHAPv2 is an EAP method primarily used for password-based user authentication, not for MAC-based authentication bypass.

BEAP-TLS

EAP-TLS is a certificate-based EAP method used for strong 802.1X authentication, not for MAB where 802.1X is unsupported.

CPAP

PAP (Password Authentication Protocol) is an older, less secure authentication method that transmits credentials in plain text and is not directly related to enabling MAB for devices lacking 802.1X support.

DProcess Host LookupCorrect

For Cisco ISE to perform MAC Authentication Bypass (MAB) for devices that do not support 802.1X, such as legacy printers, the "Process Host Lookup" option must be enabled in the Authentication Policy's Allowed Protocols list. This setting instructs ISE to look up the connecting device's MAC address against an internal identity store or endpoint database for authentication.

Concept tested: Cisco ISE MAB configuration for non-802.1X devices

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0100.html#concept_DE8F394C01C54F1FA9D1F493DF53B8DD

Topics

#Cisco ISE#MAC Authentication Bypass (MAB)#Authentication Policy#Wired Network Security

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice