nerdexam
Cisco

300-715 · Question #317

An engineer wants to preselect AD groups to be used in the access policy after integrating Cisco ISE with an active directory. Which configuration steps must the engineer take to assign groups to…

The correct answer is A. external identity sources > active directory > groups. To preselect Active Directory groups for use in Cisco ISE access policies, navigate to "external identity sources," then select "active directory," and finally go to the "groups" tab.

Architecture and Deployment

Question

An engineer wants to preselect AD groups to be used in the access policy after integrating Cisco ISE with an active directory. Which configuration steps must the engineer take to assign groups to the AD on the identity management page?

Options

  • Aexternal identity sources > active directory > groups
  • Buser identity groups > groups
  • Cexternal identity sources > groups > active directory
  • Dgroups > user identity groups

How the community answered

(32 responses)
  • A
    94% (30)
  • C
    3% (1)
  • D
    3% (1)

Why each option

To preselect Active Directory groups for use in Cisco ISE access policies, navigate to "external identity sources," then select "active directory," and finally go to the "groups" tab.

Aexternal identity sources > active directory > groupsCorrect

After integrating Cisco ISE with an Active Directory, you access the AD configuration under "Administration > Identity Management > External Identity Sources." Within the specific Active Directory instance, there's a "Groups" tab where you can "Add Groups From Directory" to import and assign specific AD groups to ISE, making them available for use in authorization policies.

Buser identity groups > groups

"User identity groups" are for local ISE groups, not for importing and managing external AD groups.

Cexternal identity sources > groups > active directory

The navigation path "external identity sources > groups > active directory" is syntactically incorrect; "groups" is a tab within the AD configuration, not a level before it.

Dgroups > user identity groups

"Groups > user identity groups" is also an incorrect navigation path and refers to local ISE groups.

Concept tested: Cisco ISE Active Directory Group Import

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_ADF3CE44C078440798C02B903E016839

Topics

#Cisco ISE#Active Directory Integration#Identity Sources#Group Management

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice