nerdexam
Cisco

300-715 · Question #327

A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA…

The correct answer is D. reauth. When a switch port exhibits multiple sessions, the RADIUS Change of Authorization (CoA) 'reauth' command should be used. This forces devices on the port to re-authenticate with Cisco ISE, allowing for updated policy enforcement.

Policy Enforcement

Question

A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA configuration must be used?

Options

  • Aport bounce
  • Bno CoA
  • Cexception
  • Dreauth

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    7% (2)
  • C
    3% (1)
  • D
    79% (23)

Why each option

When a switch port exhibits multiple sessions, the RADIUS Change of Authorization (CoA) 'reauth' command should be used. This forces devices on the port to re-authenticate with Cisco ISE, allowing for updated policy enforcement.

Aport bounce

Port bounce would physically reset the port, causing unnecessary disruption to all connected devices, which is more aggressive than typically needed for policy violations.

Bno CoA

No CoA would mean no action is taken, which fails to address the identified issue of multiple sessions on the port.

Cexception

Exception is not a standard RADIUS CoA action type; it refers to a policy state, not a specific CoA command to resolve multiple sessions.

DreauthCorrect

When a switch port has multiple sessions, indicating potential policy violations, a RADIUS Change of Authorization (CoA) reauthentication (reauth) is the appropriate action. This forces the device(s) on the port to re-authenticate with Cisco ISE, allowing ISE to apply updated authorization policies, which can restrict or deny access based on the identified issue without full port disruption.

Concept tested: RADIUS Change of Authorization (CoA) actions

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/b_ISE_admin_3_1_chapter_0101.html#Cisco_Reference.dita_313e61c7-c598-482d-bf41-3a216f2c3d9a

Topics

#RADIUS CoA#Cisco ISE#Policy Enforcement#Network Access Control

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice