350-701 · Question #34
An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?
The correct answer is C. CoA Reauth. To apply new policy without disruption, a CoA Reauth message forces an endpoint to re-authenticate its session with ISE.
Question
An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the endpoint to apply a new or updated policy from ISE. Which CoA type achieves this goal?
Options
- APort Bounce
- BCoA Terminate
- CCoA Reauth
- DCoA Session Query
How the community answered
(58 responses)- A2% (1)
- B5% (3)
- C93% (54)
Why each option
To apply new policy without disruption, a CoA Reauth message forces an endpoint to re-authenticate its session with ISE.
Port Bounce physically brings the port down and then back up, which disrupts the endpoint's connectivity, contrary to the requirement.
CoA Terminate immediately ends the authenticated session, which is a disruptive action.
A Change of Authorization (CoA) Reauth message forces an already authenticated endpoint to re-authenticate its session with Cisco ISE. This process triggers a new authentication flow, allowing ISE to apply updated authorization policies without physically disconnecting or 'bouncing' the port, thereby minimizing disruption to the user and application.
CoA Session Query is used to retrieve information about an existing session, not to force a re-authentication or policy update.
Concept tested: Cisco ISE Change of Authorization (CoA) types
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html#concept_06C47D1C90414B609E83BF305081E57A
Topics
Community Discussion
No community discussion yet for this question.