300-715 · Question #405
An engineer must create and sign a new certificate for all the portals in a Cisco ISE environment of a company. The company reports that wildcard certificates are blocked in the environment. Which…
The correct answer is B. Add the FQDN of each portal to the SAN field in the CSR. When wildcard certificates are not allowed, every portal FQDN must be explicitly listed. This requires adding each portal’s FQDN to the SAN (Subject Alternative Name) field of the CSR so that the resulting certificate is valid for all ISE portals after signing.
Question
An engineer must create and sign a new certificate for all the portals in a Cisco ISE environment of a company. The company reports that wildcard certificates are blocked in the environment. Which action must the engineer take before signing the certificate?
Options
- ACreate a DNS AAAA record for the FQDN of the Cisco ISE Monitoring node.
- BAdd the FQDN of each portal to the SAN field in the CSR
- CAdd the FQDN of each portal to the CN field in the CSR.
- DCreate a DNS AAA record for the FQDN of the Cisco ISE Administration node.
How the community answered
(50 responses)- A14% (7)
- B76% (38)
- C4% (2)
- D6% (3)
Explanation
When wildcard certificates are not allowed, every portal FQDN must be explicitly listed. This requires adding each portal’s FQDN to the SAN (Subject Alternative Name) field of the CSR so that the resulting certificate is valid for all ISE portals after signing.
Topics
Community Discussion
No community discussion yet for this question.