nerdexam
Cisco

300-715 · Question #393

A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements: - Users and computers must be authenticated. - User groups must be retr

The correct answer is C. MS-CHAPv2. When authenticating users against Microsoft Active Directory in Cisco ISE, the standard protocol combination is PEAP (Protected EAP) with MS-CHAPv2 as the inner authentication method. MS-CHAPv2 allows ISE to pass credentials to Active Directory for validation and supports retriev

Policy Enforcement

Question

A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements:

  • Users and computers must be authenticated.
  • User groups must be retrieved during authentication.

Which protocol must be added to the allowed protocols on the policy to authenticate the users?

Options

  • AEAP-TLS
  • BEAP-GTC
  • CMS-CHAPv2
  • DLEAP

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (24)

Explanation

When authenticating users against Microsoft Active Directory in Cisco ISE, the standard protocol combination is PEAP (Protected EAP) with MS-CHAPv2 as the inner authentication method. MS-CHAPv2 allows ISE to pass credentials to Active Directory for validation and supports retrieval of user group membership - satisfying both requirements. EAP-TLS (A) uses certificate-based authentication, not AD username/password credentials. EAP-GTC (B) is typically used with RSA SecurID or OTP tokens, not AD. LEAP (D) is a deprecated Cisco-proprietary protocol. MS-CHAPv2 must be enabled in the allowed protocols list under the ISE policy set so that PEAP/MS-CHAPv2 negotiations can succeed against AD.

Topics

#Authentication Protocols#Active Directory Integration#Cisco ISE#Group Authorization

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice