nerdexam
Cisco

300-715 · Question #276

An administrator is configuring an AD domain to be used with authentication for endpoints and users within Cisco ISE. Which two steps are required to configure this to be used as an external…

The correct answer is D. Configure Active Directory Domains. E. Add an Active Directory Join Point. To integrate an Active Directory domain with Cisco ISE for authentication, the administrator must first configure the Active Directory Domains within ISE, and then add an Active Directory Join Point to establish communication.

Architecture and Deployment

Question

An administrator is configuring an AD domain to be used with authentication for endpoints and users within Cisco ISE. Which two steps are required to configure this to be used as an external identity store? (Choose two.)

Options

  • AAdd an Authentication Joint Point.
  • BConfigure Authentication Domains.
  • CConfigure Active Directory Schema.
  • DConfigure Active Directory Domains.
  • EAdd an Active Directory Join Point.

How the community answered

(34 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    94% (32)

Why each option

To integrate an Active Directory domain with Cisco ISE for authentication, the administrator must first configure the Active Directory Domains within ISE, and then add an Active Directory Join Point to establish communication.

AAdd an Authentication Joint Point.

'Authentication Joint Point' is not a standard Cisco ISE configuration term related to Active Directory integration.

BConfigure Authentication Domains.

'Authentication Domains' is not the correct specific term for integrating an AD domain; the steps involve configuring the AD domain and joining it.

CConfigure Active Directory Schema.

Configuring (or modifying) the Active Directory Schema is a task performed directly within Active Directory, typically for specific applications, but it's not a required step within Cisco ISE to enable AD as an external identity store for authentication.

DConfigure Active Directory Domains.Correct

Configuring Active Directory Domains in Cisco ISE defines the AD domain(s) that ISE will interact with, specifying properties like DNS domain name. This is a foundational step before ISE can attempt to join the domain.

EAdd an Active Directory Join Point.Correct

An Active Directory Join Point is created within Cisco ISE to specify the details for ISE to join the Active Directory domain as a machine account. This join point enables secure communication and allows ISE to query AD for user and group information.

Concept tested: Cisco ISE Active Directory integration steps

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_01010.html

Topics

#Cisco ISE#Active Directory Integration#External Identity Source#Authentication Configuration

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice