300-715 · Question #350
A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices. Which two features must be enabled to meet the requirement?…
The correct answer is D. Cisco ISE internal CA service must be enabled. E. A certificate provisioning portal must be configured. To allow BYOD users to submit Certificate Signing Requests (CSRs) through their end devices, the Cisco ISE internal CA service must be enabled, and a certificate provisioning portal must be configured.
Question
A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices. Which two features must be enabled to meet the requirement? (Choose two.)
Options
- ADefine a certificate group tag.
- BA new BYOD portal must be created.
- CAdd SuperAdmin account into portal admin group.
- DCisco ISE internal CA service must be enabled.
- EA certificate provisioning portal must be configured.
How the community answered
(47 responses)- A13% (6)
- B9% (4)
- C2% (1)
- D77% (36)
Why each option
To allow BYOD users to submit Certificate Signing Requests (CSRs) through their end devices, the Cisco ISE internal CA service must be enabled, and a certificate provisioning portal must be configured.
Defining a certificate group tag is used for grouping certificates but is not a prerequisite for enabling users to submit CSRs.
While a BYOD portal is generally used for the BYOD flow, the more specific requirement for CSR submission and certificate enrollment points to the certificate provisioning portal.
Adding a SuperAdmin account to a portal admin group is related to administrative access to the portal, not to enabling the fundamental functionality for users to submit CSRs.
Enabling the Cisco ISE internal CA service is essential for ISE to act as a Certificate Authority, which is necessary for issuing certificates for BYOD devices once CSRs are submitted.
A certificate provisioning portal is specifically designed to allow end-users to enroll their devices, submit CSRs, and obtain certificates, fulfilling the requirement for users to submit CSRs through end devices.
Concept tested: Cisco ISE BYOD certificate provisioning
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01101.html
Topics
Community Discussion
No community discussion yet for this question.