nerdexam
Cisco

300-715 · Question #268

An administrator is configuring MAB and needs to create profiling policies to support devices that do not match the built-in profiles. Which two steps must the administrator take in order to use…

The correct answer is B. Use the profiling policies as the matching conditions in each authorization policy E. Feed the profiling policies into a logical profile and use the logical profile in the authorization. To use custom profiling policies in authorization, they must either be directly used as conditions in authorization policies or be grouped into a logical profile that is then referenced by authorization policies.

Policy Enforcement

Question

An administrator is configuring MAB and needs to create profiling policies to support devices that do not match the built-in profiles. Which two steps must the administrator take in order to use these new profiles in authorization policies? (Choose two.)

Options

  • AEdit the authorization policy to give the profiles as a result of the authentication and authorization
  • BUse the profiling policies as the matching conditions in each authorization policy
  • CModify the endpoint identity group to feed the profiling policies into and match the parent group in
  • DConfigure the profiling policy to make a matching identity group and use the group in the
  • EFeed the profiling policies into a logical profile and use the logical profile in the authorization

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    69% (20)
  • C
    3% (1)
  • D
    17% (5)

Why each option

To use custom profiling policies in authorization, they must either be directly used as conditions in authorization policies or be grouped into a logical profile that is then referenced by authorization policies.

AEdit the authorization policy to give the profiles as a result of the authentication and authorization

Authorization policies use profiling policies as conditions to determine the outcome, not as results themselves.

BUse the profiling policies as the matching conditions in each authorization policyCorrect

Profiling policies classify endpoints based on attributes. For an authorization policy to grant access based on these classifications, the profiling policy must be used as a condition to match the endpoint's profile.

CModify the endpoint identity group to feed the profiling policies into and match the parent group in

While endpoints are part of identity groups, profiling policies themselves are not directly fed into or matched by endpoint identity groups for use in authorization.

DConfigure the profiling policy to make a matching identity group and use the group in the

Profiling policies do not directly 'make a matching identity group'; they assign a profile, and endpoints can be assigned to identity groups based on these profiles, but the primary way to use profiling policies directly in authorization is via conditions or logical profiles.

EFeed the profiling policies into a logical profile and use the logical profile in the authorizationCorrect

Logical profiles allow combining multiple profiling policies or conditions into a single entity, simplifying authorization policies by providing a consolidated condition that represents a specific type or group of devices. Authorization policies can then reference this logical profile.

Concept tested: Cisco ISE profiling policy integration with authorization

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0100.html

Topics

#Profiling Policies#Authorization Conditions#Logical Profiles#Cisco ISE

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice