300-740 · Question #3
An administrator must deploy an endpoint posture policy for all users. The organization wants to have all endpoints checked against antimalware definitions and operating system updates and ensure…
The correct answer is C. Create the required posture policy within Cisco ISE, configure redirection on the NAD, and ensure. Option C is correct because Cisco ISE is the authoritative posture policy engine in a Cisco security architecture - it natively supports antimalware definition checks, OS patch-level validation, and Secure Client module verification through its posture conditions and policies…
Question
An administrator must deploy an endpoint posture policy for all users. The organization wants to have all endpoints checked against antimalware definitions and operating system updates and ensure that the correct Secure Client modules are installed properly. How must the administrator meet the requirements?
Options
- AConfigure the WLC to provide local posture services, and configure Cisco ISE to receive the
- BCreate an ASA Firewall posture policy, upload the Secure Client images to the NAD, and create a
- CCreate the required posture policy within Cisco ISE, configure redirection on the NAD, and ensure
- DIdentify the antimalware being used, create an endpoint script to ensure that it is updated, and
How the community answered
(40 responses)- A8% (3)
- B3% (1)
- C85% (34)
- D5% (2)
Explanation
Option C is correct because Cisco ISE is the authoritative posture policy engine in a Cisco security architecture - it natively supports antimalware definition checks, OS patch-level validation, and Secure Client module verification through its posture conditions and policies. The NAD (Network Access Device, e.g., a switch or WLC) must be configured for redirection so that non-compliant endpoints are steered to ISE for assessment and remediation, while the Secure Client agent on the endpoint communicates posture results back to ISE.
Why the distractors fail:
- A is wrong because the WLC is a NAD, not a posture engine - it redirects clients to ISE, it doesn't run posture services locally.
- B is wrong because ASA Firewall VPN posture is scoped to remote-access VPN sessions, not an enterprise-wide endpoint compliance solution; also, Secure Client images are provisioned through ISE Client Provisioning, not uploaded to the NAD.
- D is wrong because custom endpoint scripts bypass ISE's framework entirely, don't scale, and lack centralized reporting or enforcement.
Memory tip: Think "ISE owns the brain, NAD owns the door." ISE defines what to check (posture policy), the NAD controls who gets in (redirection/enforcement), and Secure Client is the on-device agent that reports compliance - all three must work together, with ISE at the center.
Topics
Community Discussion
No community discussion yet for this question.