nerdexam
Cisco

300-715 · Question #273

An organization has a SGACL locally configured on a switch port, but when a user in the Executives group connects to the network, they receive a different level of network access than expected. When C

The correct answer is D. The policies are merged, but dynamically downloaded policies receive priority.. When both local and dynamically downloaded Security Group Access Control Lists (SGACLs) exist for a user, the switch merges them, with the dynamically downloaded policies from Cisco ISE taking precedence.

Policy Enforcement

Question

An organization has a SGACL locally configured on a switch port, but when a user in the Executives group connects to the network, they receive a different level of network access than expected. When Cisco ISE pushes SGACLs to the switch after the authorization phase, how does the switch decide which access to grant the user?

Options

  • ADynamically downloaded policies override local policies in all cases.
  • BLocal policies override dynamically downloaded policies in all cases.
  • CThe policies are merged, but local policies receive priority.
  • DThe policies are merged, but dynamically downloaded policies receive priority.

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    10% (2)
  • D
    86% (18)

Why each option

When both local and dynamically downloaded Security Group Access Control Lists (SGACLs) exist for a user, the switch merges them, with the dynamically downloaded policies from Cisco ISE taking precedence.

ADynamically downloaded policies override local policies in all cases.

While dynamically downloaded policies do override local policies, the term 'in all cases' is too absolute; it's more accurate to say they receive priority in a merge scenario.

BLocal policies override dynamically downloaded policies in all cases.

This is incorrect; dynamically downloaded policies from ISE typically take precedence over local configurations.

CThe policies are merged, but local policies receive priority.

While the policies are merged, dynamically downloaded policies receive priority, not local policies.

DThe policies are merged, but dynamically downloaded policies receive priority.Correct

In Cisco TrustSec, when a switch has both a locally configured SGACL on a port and receives a dynamically downloaded SGACL from Cisco ISE during authorization, the switch merges these policies. However, dynamically downloaded policies (from ISE) are given priority over locally configured policies for the endpoint.

Concept tested: Cisco TrustSec SGACL policy precedence

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec-guide/sg_acls.html

Topics

#SGACL#Cisco ISE#Policy Enforcement#Policy Precedence

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice