nerdexam
Cisco

300-715 · Question #281

An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redire

The correct answer is A. an authorization profile. To redirect users who fail 802.1X authentication to a web portal and restrict their access with an ACL, an authorization profile must be configured in Cisco ISE.

Policy Enforcement

Question

An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redirection and have their access restricted via an ACL. What must be configured in Cisco ISE to accomplish this task?

Options

  • Aan authorization profile
  • Ban authorization rule
  • Can authentication policy
  • Dan authentication profile

How the community answered

(66 responses)
  • A
    94% (62)
  • B
    2% (1)
  • D
    5% (3)

Why each option

To redirect users who fail 802.1X authentication to a web portal and restrict their access with an ACL, an authorization profile must be configured in Cisco ISE.

Aan authorization profileCorrect

An authorization profile in Cisco ISE defines the specific actions and attributes, such as URL redirection for web-based access or the application of Downloadable ACLs (dACLs), that are applied to an endpoint after authentication and subsequent authorization.

Ban authorization rule

An authorization rule defines the conditions under which an authorization profile is applied, but the profile itself contains the specific actions like web redirection and ACL application.

Can authentication policy

An authentication policy specifies which authentication protocols and identity stores to use, but it does not define the actions to take after authentication.

Dan authentication profile

An authentication profile specifies how authentication is performed (e.g., certificate authentication profile), but it does not dictate the authorization outcomes such as redirection or ACL assignment.

Concept tested: Cisco ISE authorization profiles for access control

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_0100.html

Topics

#Cisco ISE#802.1X#Authorization Profile#ACL Enforcement

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice