nerdexam
Cisco

300-715 · Question #387

An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These config

The correct answer is C. authorization policy that has the PermitAccess permission and matches the allowlist identity. In Cisco ISE, MAB (MAC Authentication Bypass) requires both an authentication policy and an authorization policy. The scenario already has an authentication policy configured for MAB users and an endpoint identity group (allowlist) with the MAC addresses enrolled. The missing pie

Policy Enforcement

Question

An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These configurations were performed:

  • configured an identity group named allowlist
  • configured the endpoints to use the MAC address of incompatible

802.1X devices

  • added the endpoints to the allowlist identity group
  • configured an authentication policy for MAB users

What must be configured?

Options

  • Alogical profile that matches the allowlist identity group based on the configured policy
  • Bauthorization profile that has the PermitAccess permission and matches the allowlist identity
  • Cauthorization policy that has the PermitAccess permission and matches the allowlist identity
  • Dauthentication profile that has the PermitAccess permission and matches the allowlist identity

How the community answered

(43 responses)
  • B
    2% (1)
  • C
    95% (41)
  • D
    2% (1)

Explanation

In Cisco ISE, MAB (MAC Authentication Bypass) requires both an authentication policy and an authorization policy. The scenario already has an authentication policy configured for MAB users and an endpoint identity group (allowlist) with the MAC addresses enrolled. The missing piece is an authorization policy - this is what ISE evaluates after authentication to determine what access to grant. The authorization policy must reference the allowlist identity group as a condition and apply the PermitAccess result. Option B is wrong because an authorization profile defines the access attributes (e.g., VLAN, ACL), while an authorization policy is the rule that matches conditions (like identity group membership) and maps them to that profile or a result like PermitAccess. Option A (logical profile) and D (authentication profile) are not valid ISE constructs for this purpose.

Topics

#Cisco ISE#MAC Authentication Bypass (MAB)#Authorization Policy#Identity Groups

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice