nerdexam
Cisco

300-715 · Question #279

A network engineer is configuring a new certificate template on the internal CA within Cisco ISE to provision certificates to BYOD devices that must be enrolled in the network. What must be…

The correct answer is A. MAC address. To uniquely identify BYOD devices in Cisco ISE after enrollment, the MAC address of the device must be configured in the Subject Alternative Name (SAN) field of the certificate template issued by the internal CA.

BYOD

Question

A network engineer is configuring a new certificate template on the internal CA within Cisco ISE to provision certificates to BYOD devices that must be enrolled in the network. What must be configured in the SAN field of the certificate to identify the devices after enrollment?

Options

  • AMAC address
  • Bemail address
  • Cuser principal name
  • Dcommon name

How the community answered

(19 responses)
  • A
    89% (17)
  • C
    5% (1)
  • D
    5% (1)

Why each option

To uniquely identify BYOD devices in Cisco ISE after enrollment, the MAC address of the device must be configured in the Subject Alternative Name (SAN) field of the certificate template issued by the internal CA.

AMAC addressCorrect

For BYOD devices in Cisco ISE, especially when performing certificate-based authentication (e.g., EAP-TLS), the device's MAC address is often used as a unique identifier. Including the MAC address in the SAN field allows ISE to correlate the presented certificate with the device's identity registered during the BYOD onboarding process.

Bemail address

An email address is typically associated with a user, not a unique device identity for network access control purposes like BYOD device identification.

Cuser principal name

A user principal name (UPN) is associated with a user identity, primarily in Active Directory, and is not a standard unique identifier for a device in the context of network access control.

Dcommon name

While the common name (CN) can identify the device, the SAN field is designed to hold multiple alternative identities, and using the MAC address specifically in the SAN is a common and recommended practice for device identification in BYOD scenarios with certificates.

Concept tested: Cisco ISE BYOD device certificate identification

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ISE_admin_guide_27/b_ISE_admin_guide_27_chapter_0110.html#concept_F7DCCBBE1FBB427D8916361C102C30F9

Topics

#Cisco ISE#BYOD#Certificates#Device Identification

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice