300-715 · Question #276
An administrator is configuring an AD domain to be used with authentication for endpoints and users within Cisco ISE. Which two steps are required to configure this to be used as an external…
The correct answer is D. Configure Active Directory Domains. E. Add an Active Directory Join Point. To integrate an Active Directory domain with Cisco ISE for authentication, the administrator must first configure the Active Directory Domains within ISE, and then add an Active Directory Join Point to establish communication.
Question
An administrator is configuring an AD domain to be used with authentication for endpoints and users within Cisco ISE. Which two steps are required to configure this to be used as an external identity store? (Choose two.)
Options
- AAdd an Authentication Joint Point.
- BConfigure Authentication Domains.
- CConfigure Active Directory Schema.
- DConfigure Active Directory Domains.
- EAdd an Active Directory Join Point.
How the community answered
(34 responses)- A3% (1)
- C3% (1)
- D94% (32)
Why each option
To integrate an Active Directory domain with Cisco ISE for authentication, the administrator must first configure the Active Directory Domains within ISE, and then add an Active Directory Join Point to establish communication.
'Authentication Joint Point' is not a standard Cisco ISE configuration term related to Active Directory integration.
'Authentication Domains' is not the correct specific term for integrating an AD domain; the steps involve configuring the AD domain and joining it.
Configuring (or modifying) the Active Directory Schema is a task performed directly within Active Directory, typically for specific applications, but it's not a required step within Cisco ISE to enable AD as an external identity store for authentication.
Configuring Active Directory Domains in Cisco ISE defines the AD domain(s) that ISE will interact with, specifying properties like DNS domain name. This is a foundational step before ISE can attempt to join the domain.
An Active Directory Join Point is created within Cisco ISE to specify the details for ISE to join the Active Directory domain as a machine account. This join point enables secure communication and allows ISE to query AD for user and group information.
Concept tested: Cisco ISE Active Directory integration steps
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_01010.html
Topics
Community Discussion
No community discussion yet for this question.