350-701 · Question #564
An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE. Which action accomplishes this task?
The correct answer is C. Modify the DHCP relay and point the IP address to Cisco ISE. Under the same interfaces, another ip helper-address command is configured to point to the ISE PSN interface enabled with the DHCP probe. The ISE Policy Service node will not reply to these packets, but the goal is simply to send a copy of the requests to ISE for parsing of…
Question
An engineer is implementing DHCP security mechanisms and needs the ability to add additional attributes to profiles that are created within Cisco ISE. Which action accomplishes this task?
Options
- ADefine MAC-to-lP address mappings in the switch to ensure that rogue devices cannot get an IP
- BUse DHCP option 82 to ensure that the request is from a legitimate endpoint and send the
- CModify the DHCP relay and point the IP address to Cisco ISE
- DConfigure DHCP snooping on the switch VLANs and trust the necessary interfaces
How the community answered
(28 responses)- A7% (2)
- B4% (1)
- C82% (23)
- D7% (2)
Explanation
Under the same interfaces, another ip helper-address command is configured to point to the ISE PSN interface enabled with the DHCP probe. The ISE Policy Service node will not reply to these packets, but the goal is simply to send a copy of the requests to ISE for parsing of DHCP attributes. It is possible to configure multiple IP Helper targets on Cisco devices to allow multiple ISE Policy Service nodes to receive copies of the DHCP requests. https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta- p/3739456#toc-hId-826550277
Topics
Community Discussion
No community discussion yet for this question.