300-715 · Question #272
A client connects to a network and the authenticator device learns the MAC address 11:22:33:44:55:AA of this client. After the MAC address is learned, the 802.1 x authentication process begins on…
The correct answer is C. closed mode. Closed mode in Cisco ISE deployment is characterized by a 'deny all by default' posture: all traffic is blocked on a port until 802.1X authentication succeeds. Upon successful authentication, ISE applies a downloadable ACL (dACL) or VLAN assignment to grant appropriate access…
Question
A client connects to a network and the authenticator device learns the MAC address 11:22:33:44:55:AA of this client. After the MAC address is learned, the 802.1 x authentication process begins on this port. Which ISE deployment mode restricts all traffic initially, applies a rule for access control if 802.1x authentication is successful, and can be configured to grant only limited access if 802.1 x authentication is unsuccessful?
Options
- Aopen mode
- Bmonitor mode
- Cclosed mode
- Dlow-impact mode
How the community answered
(44 responses)- A5% (2)
- B2% (1)
- C93% (41)
Explanation
Closed mode in Cisco ISE deployment is characterized by a 'deny all by default' posture: all traffic is blocked on a port until 802.1X authentication succeeds. Upon successful authentication, ISE applies a downloadable ACL (dACL) or VLAN assignment to grant appropriate access. If authentication fails, the port can be configured to grant limited or restricted access (e.g., a guest VLAN or a restrictive ACL). This matches all three criteria in the question. Monitor mode (B) logs authentication events but permits all traffic regardless of outcome - used for visibility without enforcement. Open mode (A) allows traffic before and after authentication, applying policy only after success. Low-impact mode (D) permits some pre-authentication traffic using a pre-auth ACL, then applies full policy after authentication.
Topics
Community Discussion
No community discussion yet for this question.