300-715 · Question #342
An engineer must use certificate authentication for endpoints that connect to a wired network with a Cisco ISE deployment. The engineer must define the certificate field used as the principal…
The correct answer is D. authentication profile. To define which certificate field serves as the principal username for certificate authentication in Cisco ISE, an authentication profile must be configured.
Question
An engineer must use certificate authentication for endpoints that connect to a wired network with a Cisco ISE deployment. The engineer must define the certificate field used as the principal username. What is needed to complete the configuration?
Options
- Aauthorization profile
- Bauthentication policy
- Cauthorization rule
- Dauthentication profile
How the community answered
(42 responses)- A2% (1)
- B12% (5)
- C5% (2)
- D81% (34)
Why each option
To define which certificate field serves as the principal username for certificate authentication in Cisco ISE, an authentication profile must be configured.
An authorization profile defines the access permissions and attributes granted to an authenticated user, not how the user is authenticated.
An authentication policy determines which authentication protocol and identity source sequence to use based on specific conditions, but the detailed mapping of certificate fields to username is within the authentication profile.
An authorization rule matches conditions to an authorization profile to determine access, it does not define certificate field mapping for authentication.
An authentication profile in Cisco ISE is used to define how endpoints are authenticated, including specifying the identity store sequence and which certificate attribute (like SAN or CN) will be used as the username for certificate-based authentication.
Concept tested: Cisco ISE certificate authentication profiles
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html
Topics
Community Discussion
No community discussion yet for this question.