300-715 · Question #268
An administrator is configuring MAB and needs to create profiling policies to support devices that do not match the built-in profiles. Which two steps must the administrator take in order to use…
The correct answer is B. Use the profiling policies as the matching conditions in each authorization policy E. Feed the profiling policies into a logical profile and use the logical profile in the authorization. To use custom profiling policies in authorization, they must either be directly used as conditions in authorization policies or be grouped into a logical profile that is then referenced by authorization policies.
Question
An administrator is configuring MAB and needs to create profiling policies to support devices that do not match the built-in profiles. Which two steps must the administrator take in order to use these new profiles in authorization policies? (Choose two.)
Options
- AEdit the authorization policy to give the profiles as a result of the authentication and authorization
- BUse the profiling policies as the matching conditions in each authorization policy
- CModify the endpoint identity group to feed the profiling policies into and match the parent group in
- DConfigure the profiling policy to make a matching identity group and use the group in the
- EFeed the profiling policies into a logical profile and use the logical profile in the authorization
How the community answered
(29 responses)- A10% (3)
- B69% (20)
- C3% (1)
- D17% (5)
Why each option
To use custom profiling policies in authorization, they must either be directly used as conditions in authorization policies or be grouped into a logical profile that is then referenced by authorization policies.
Authorization policies use profiling policies as conditions to determine the outcome, not as results themselves.
Profiling policies classify endpoints based on attributes. For an authorization policy to grant access based on these classifications, the profiling policy must be used as a condition to match the endpoint's profile.
While endpoints are part of identity groups, profiling policies themselves are not directly fed into or matched by endpoint identity groups for use in authorization.
Profiling policies do not directly 'make a matching identity group'; they assign a profile, and endpoints can be assigned to identity groups based on these profiles, but the primary way to use profiling policies directly in authorization is via conditions or logical profiles.
Logical profiles allow combining multiple profiling policies or conditions into a single entity, simplifying authorization policies by providing a consolidated condition that represents a specific type or group of devices. Authorization policies can then reference this logical profile.
Concept tested: Cisco ISE profiling policy integration with authorization
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.