300-715 · Question #281
An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redire
The correct answer is A. an authorization profile. To redirect users who fail 802.1X authentication to a web portal and restrict their access with an ACL, an authorization profile must be configured in Cisco ISE.
Question
An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redirection and have their access restricted via an ACL. What must be configured in Cisco ISE to accomplish this task?
Options
- Aan authorization profile
- Ban authorization rule
- Can authentication policy
- Dan authentication profile
How the community answered
(66 responses)- A94% (62)
- B2% (1)
- D5% (3)
Why each option
To redirect users who fail 802.1X authentication to a web portal and restrict their access with an ACL, an authorization profile must be configured in Cisco ISE.
An authorization profile in Cisco ISE defines the specific actions and attributes, such as URL redirection for web-based access or the application of Downloadable ACLs (dACLs), that are applied to an endpoint after authentication and subsequent authorization.
An authorization rule defines the conditions under which an authorization profile is applied, but the profile itself contains the specific actions like web redirection and ACL application.
An authentication policy specifies which authentication protocols and identity stores to use, but it does not define the actions to take after authentication.
An authentication profile specifies how authentication is performed (e.g., certificate authentication profile), but it does not dictate the authorization outcomes such as redirection or ACL assignment.
Concept tested: Cisco ISE authorization profiles for access control
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.