300-715 · Question #61
What is the condition that a Cisco ISE authorization policy cannot match?
The correct answer is B. custom. Cisco ISE authorization policies cannot directly match on "custom" as a condition type; instead, custom conditions are built using various attributes from dictionaries or external sources.
Question
What is the condition that a Cisco ISE authorization policy cannot match?
Options
- Acompany contact
- Bcustom
- Ctime
- Ddevice type
- Eposture
How the community answered
(30 responses)- A3% (1)
- B83% (25)
- D3% (1)
- E10% (3)
Why each option
Cisco ISE authorization policies cannot directly match on "custom" as a condition type; instead, custom conditions are built using various attributes from dictionaries or external sources.
Company contact can be used as an attribute in an authorization policy, especially if integrated with an external identity source that provides this information.
Cisco ISE authorization policies leverage a wide range of attributes (such as device type, time of day, user group, posture status, etc.) to define conditions. While you can create highly customized policies using combinations of these attributes, 'custom' itself is not a predefined, selectable condition category or attribute that an authorization policy matches against.
Time (e.g., time of day, day of week) is a common and supported condition for authorization policies in Cisco ISE to restrict access based on schedule.
Device type (e.g., IP phone, printer, laptop) is a fundamental profiling attribute used extensively in Cisco ISE authorization policies.
Posture (compliance status of an endpoint) is a critical condition in Cisco ISE authorization policies, determining access based on whether a device meets security requirements.
Concept tested: Cisco ISE authorization policy conditions
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_31/b_ise_admin_31_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.