300-715 · Question #391
A network security administrator wants to integrate Cisco ISE with Active Directory. Which configuration action must the security administrator take to accomplish the task?
The correct answer is D. Join Cisco ISE to the Active Directory domain. To integrate Cisco ISE with Microsoft Active Directory, the fundamental prerequisite is that ISE must join the AD domain (Administration > Identity Management > External Identity Sources > Active Directory > Add > Join). This domain-join operation creates a machine account for…
Question
A network security administrator wants to integrate Cisco ISE with Active Directory. Which configuration action must the security administrator take to accomplish the task?
Options
- ASearch Active Directory to see if admin user account exists.
- BRemove the ISE machine account from the domain.
- CRemove Cisco ISE user account from the domain.
- DJoin Cisco ISE to the Active Directory domain.
How the community answered
(58 responses)- A3% (2)
- B2% (1)
- D95% (55)
Explanation
To integrate Cisco ISE with Microsoft Active Directory, the fundamental prerequisite is that ISE must join the AD domain (Administration > Identity Management > External Identity Sources > Active Directory > Add > Join). This domain-join operation creates a machine account for ISE in AD and establishes the trust relationship required for ISE to query AD for user authentication, group membership, and attribute lookups. Options A, B, and C describe incorrect or irrelevant actions: searching AD for an admin account is not a configuration action, and removing machine or user accounts from the domain would break integration rather than enable it.
Topics
Community Discussion
No community discussion yet for this question.