nerdexam
Cisco

300-715 · Question #350

A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices. Which two features must be enabled to meet the requirement?…

The correct answer is D. Cisco ISE internal CA service must be enabled. E. A certificate provisioning portal must be configured. To allow BYOD users to submit Certificate Signing Requests (CSRs) through their end devices, the Cisco ISE internal CA service must be enabled, and a certificate provisioning portal must be configured.

BYOD

Question

A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices. Which two features must be enabled to meet the requirement? (Choose two.)

Options

  • ADefine a certificate group tag.
  • BA new BYOD portal must be created.
  • CAdd SuperAdmin account into portal admin group.
  • DCisco ISE internal CA service must be enabled.
  • EA certificate provisioning portal must be configured.

How the community answered

(47 responses)
  • A
    13% (6)
  • B
    9% (4)
  • C
    2% (1)
  • D
    77% (36)

Why each option

To allow BYOD users to submit Certificate Signing Requests (CSRs) through their end devices, the Cisco ISE internal CA service must be enabled, and a certificate provisioning portal must be configured.

ADefine a certificate group tag.

Defining a certificate group tag is used for grouping certificates but is not a prerequisite for enabling users to submit CSRs.

BA new BYOD portal must be created.

While a BYOD portal is generally used for the BYOD flow, the more specific requirement for CSR submission and certificate enrollment points to the certificate provisioning portal.

CAdd SuperAdmin account into portal admin group.

Adding a SuperAdmin account to a portal admin group is related to administrative access to the portal, not to enabling the fundamental functionality for users to submit CSRs.

DCisco ISE internal CA service must be enabled.Correct

Enabling the Cisco ISE internal CA service is essential for ISE to act as a Certificate Authority, which is necessary for issuing certificates for BYOD devices once CSRs are submitted.

EA certificate provisioning portal must be configured.Correct

A certificate provisioning portal is specifically designed to allow end-users to enroll their devices, submit CSRs, and obtain certificates, fulfilling the requirement for users to submit CSRs through end devices.

Concept tested: Cisco ISE BYOD certificate provisioning

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01101.html

Topics

#BYOD#Cisco ISE#Certificate Provisioning#Internal CA

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice