nerdexam
Cisco

300-715 · Question #303

What is configured to enforce the blocklist permissions and deny access to clients in the blocklist to protect against a lost or stolen device obtaining access to the network?

The correct answer is D. Authorization rule. An Authorization rule is configured in Cisco ISE to enforce blocklist permissions, denying network access to clients on the blocklist, thereby protecting against unauthorized device access.

Policy Enforcement

Question

What is configured to enforce the blocklist permissions and deny access to clients in the blocklist to protect against a lost or stolen device obtaining access to the network?

Options

  • AMy Devices portal
  • Bblocklist portal
  • CAuthentication rule
  • DAuthorization rule

How the community answered

(26 responses)
  • A
    8% (2)
  • C
    4% (1)
  • D
    88% (23)

Why each option

An Authorization rule is configured in Cisco ISE to enforce blocklist permissions, denying network access to clients on the blocklist, thereby protecting against unauthorized device access.

AMy Devices portal

The My Devices portal is where users manage their own registered devices, not where blocklist enforcement rules are configured.

Bblocklist portal

A 'blocklist portal' is not a standard or direct mechanism in ISE for enforcing blocklist permissions.

CAuthentication rule

An Authentication rule determines if a user or device is who they claim to be, but it does not specify what level of access they receive or if they are blocked.

DAuthorization ruleCorrect

An Authorization rule in Cisco ISE determines what network access a client is granted or denied after authentication. To enforce a blocklist, an authorization policy is specifically configured to match clients present in the blocklist and assign a 'Deny Access' or highly restricted result, effectively preventing them from gaining network access.

Concept tested: Cisco ISE Authorization Rules and Blocklist Enforcement

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0100.html#concept_CE990B01D2194883A3B83E153D41673C

Topics

#Authorization Policies#Blocklist Enforcement#Device Access Control#Cisco ISE

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice