300-715 · Question #368
An administrator must onboard MacOS endpoints that connect to Cisco switches using the BYOD portal in Cisco ISE. The authentication method must be configured to meet these requirements: - Cisco ISE id
The correct answer is A. EAP-TLS. EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) is the only protocol among the choices that mandates mutual certificate-based authentication. The scenario describes: (1) ISE presenting its server certificate to the endpoint, (2) the endpoint validating tha
Question
An administrator must onboard MacOS endpoints that connect to Cisco switches using the BYOD portal in Cisco ISE. The authentication method must be configured to meet these requirements:
- Cisco ISE identifies itself by providing its identity certificate to
the endpoint.
- The endpoint validates the Cisco ISE identity certificate.
- The endpoint provides its endpoint identity certificate, signed by
Cisco ISE, to Cisco ISE.
- Cisco ISE confirms the endpoint certificate validity, and the
endpoint is authorized onto the network. Which protocol must be configured?
Options
- AEAP-TLS
- BEAP-GTC
- CEAP-FAST
- DEAP-TTLS
How the community answered
(36 responses)- A83% (30)
- B8% (3)
- C6% (2)
- D3% (1)
Explanation
EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) is the only protocol among the choices that mandates mutual certificate-based authentication. The scenario describes: (1) ISE presenting its server certificate to the endpoint, (2) the endpoint validating that certificate, (3) the endpoint presenting its own client certificate (signed by ISE's Internal CA via BYOD onboarding) back to ISE, and (4) ISE validating the client certificate. This bidirectional certificate exchange is the defining characteristic of EAP-TLS. EAP-GTC, EAP-FAST, and EAP-TTLS do not require the endpoint to present a certificate in the same mutual-auth manner.
Topics
Community Discussion
No community discussion yet for this question.