nerdexam
Cisco

300-715 · Question #348

An endpoint with the MAC address 04:85:70:26:64:AB attempts to connect to the network. The security administrator wants to ensure that before authentication, only limited access is provided for…

The correct answer is A. low-impact mode. To provide limited network access before successful authentication and full access afterward, the administrator should configure Cisco ISE in low-impact mode.

Architecture and Deployment

Question

An endpoint with the MAC address 04:85:70:26:64:AB attempts to connect to the network. The security administrator wants to ensure that before authentication, only limited access is provided for services including DHCP and DNS Full network access is only granted upon successful 802.1X authentication. Which ISE deployment mode should the administrator configure to meet the requirements?

Options

  • Alow-impact mode
  • Bclosed mode
  • Cmonitor mode
  • Dopen mode

How the community answered

(43 responses)
  • A
    95% (41)
  • B
    2% (1)
  • D
    2% (1)

Why each option

To provide limited network access before successful authentication and full access afterward, the administrator should configure Cisco ISE in low-impact mode.

Alow-impact modeCorrect

Low-impact mode in Cisco ISE provides initial limited network access (e.g., for DHCP and DNS) to endpoints before they are successfully authenticated, allowing necessary network configurations while preventing full access until 802.1X authentication is complete.

Bclosed mode

Closed mode prevents all network access until an endpoint is successfully authenticated and authorized, which does not meet the requirement for limited access before authentication.

Cmonitor mode

Monitor mode allows all devices full network access and simply logs authentication attempts without enforcing any restrictions, which does not meet the security requirement.

Dopen mode

Open mode allows all devices full network access without requiring authentication, which does not meet the security requirement for authentication and limited access prior to it.

Concept tested: Cisco ISE deployment modes (network access modes)

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0_CR_Guide/b_ISE_admin_3_0_CR_Guide_chapter_0110.html

Topics

#ISE Deployment Modes#802.1X Authentication#Pre-authentication Access#Network Access Control

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice