nerdexam
Cisco

300-715 · Question #266

To configure BYOD using Cisco ISE. an administrator is considering issuing certificates to the devices connecting to provide a better user experience. External CA servers cannot be used for this…

The correct answer is C. Configure the Cisco ISE Internal CA to issue certificates to each endpoint connecting to the. To issue certificates to BYOD devices locally from Cisco ISE for an improved user experience, the Cisco ISE Internal CA must be configured to provision certificates directly to each connecting endpoint.

BYOD

Question

To configure BYOD using Cisco ISE. an administrator is considering issuing certificates to the devices connecting to provide a better user experience. External CA servers cannot be used for this purpose because everything must be local to the Cisco ISE. What must be done to accomplish this?

Options

  • AUse the captive portal network assistant to issue certificates to the endpoints as they
  • BUse ISE as a sub CA for the BYOD portal and redirect users to the Root CA for certificate
  • CConfigure the Cisco ISE Internal CA to issue certificates to each endpoint connecting to the
  • DConfigure MS SCEP so that endpoints can query their local AD server for the correct certificate.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    88% (22)

Why each option

To issue certificates to BYOD devices locally from Cisco ISE for an improved user experience, the Cisco ISE Internal CA must be configured to provision certificates directly to each connecting endpoint.

AUse the captive portal network assistant to issue certificates to the endpoints as they

The captive portal network assistant is primarily for initial redirection and guest access, not for directly issuing client certificates for BYOD in a scenario where ISE itself is the CA.

BUse ISE as a sub CA for the BYOD portal and redirect users to the Root CA for certificate

This option implies that ISE acts as a sub-CA and relies on an external Root CA, which contradicts the requirement that "External CA servers cannot be used" and "everything must be local to the Cisco ISE."

CConfigure the Cisco ISE Internal CA to issue certificates to each endpoint connecting to theCorrect

When external CA servers are not permitted, the Cisco ISE Internal CA is the solution for issuing certificates to BYOD devices. By configuring the ISE Internal CA, administrators can enable ISE to act as a certificate authority itself, generating and provisioning unique client certificates to endpoints during the BYOD onboarding process for secure, certificate-based authentication.

DConfigure MS SCEP so that endpoints can query their local AD server for the correct certificate.

MS SCEP (Simple Certificate Enrollment Protocol) is used for enrolling certificates from a Microsoft CA, which is an external CA and thus goes against the requirement for everything to be local to Cisco ISE.

Concept tested: Cisco ISE Internal CA for BYOD certificate provisioning

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_admin_guide_27/b_ise_admin_guide_27_chapter_01101.html#concept_81F786B6D12D420F921B52F2E23E6C2D

Topics

#BYOD#Cisco ISE#Internal CA#Certificates

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice