300-715 · Question #320
An engineer must develop a policy that utilizes AD group membership on Cisco ISE. Which type of policy element must the engineer configure to create an AD group within a policy?
The correct answer is A. conditions. To incorporate Active Directory group membership into a Cisco ISE policy, the engineer must configure a condition that references the AD group.
Question
An engineer must develop a policy that utilizes AD group membership on Cisco ISE. Which type of policy element must the engineer configure to create an AD group within a policy?
Options
- Aconditions
- Bresults
- Cdictionaries
- Dsmart conditions
How the community answered
(23 responses)- A87% (20)
- B4% (1)
- C9% (2)
Why each option
To incorporate Active Directory group membership into a Cisco ISE policy, the engineer must configure a condition that references the AD group.
In Cisco ISE policies, conditions are used to evaluate specific criteria, such as user or endpoint attributes, to determine if a policy rule should be applied. Active Directory group membership is a common attribute used within conditions to match users belonging to particular AD groups, allowing the policy to grant or deny access accordingly.
Results define the action taken by the policy (e.g., permit access, assign VLAN) if the conditions are met; they do not define the group membership itself.
Dictionaries define the attributes that can be used in policies, but they are not the elements where specific AD groups are configured for use within a policy. AD groups are attributes referenced in conditions using dictionary values.
Smart conditions are predefined, complex conditions, but the fundamental element used to create a custom AD group check is a standard condition.
Concept tested: Cisco ISE Policy Conditions AD Group
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_DE17DE17C54E41EC8A6D02A12316E2CC
Topics
Community Discussion
No community discussion yet for this question.