nerdexam
Cisco

350-701 · Question #585

Which two Cisco ISE components enforce security policies on noncompliant endpoints by blocking network access? (Choose two.)

The correct answer is C. profiling E. posture agents. Cisco ISE enforces security policies on noncompliant endpoints by leveraging profiling to categorize devices and posture agents to assess their compliance and apply restrictions.

Submitted by renata2k· Mar 30, 2026None

Question

Which two Cisco ISE components enforce security policies on noncompliant endpoints by blocking network access? (Choose two.)

Options

  • AApex licensing
  • BTACACS+
  • Cprofiling
  • DDHCP and SNMP probes
  • Eposture agents

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    77% (27)
  • D
    14% (5)

Why each option

Cisco ISE enforces security policies on noncompliant endpoints by leveraging profiling to categorize devices and posture agents to assess their compliance and apply restrictions.

AApex licensing

Apex licensing is a tier of Cisco ISE licensing that enables advanced features like posture, but it is not a component that directly enforces security policies.

BTACACS+

TACACS+ is an authentication, authorization, and accounting (AAA) protocol primarily used for device administration access, not for enforcing network access policies on user endpoints.

CprofilingCorrect

Profiling allows ISE to categorize endpoints based on collected attributes; if an endpoint's profile indicates non-compliance with network access policies, ISE can apply restrictions or block access.

DDHCP and SNMP probes

DHCP and SNMP probes are mechanisms used by ISE to *collect* endpoint attributes for profiling, not components that *enforce* security policies by blocking access.

Eposture agentsCorrect

Posture agents, such as the Cisco AnyConnect client, run on endpoints to collect real-time security state information (e.g., anti-virus definitions, OS updates) and report non-compliance to ISE, which then enforces policy, including blocking network access.

Concept tested: Cisco ISE policy enforcement components

Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_011.html

Topics

#Cisco ISE#Endpoint Compliance#Posture Agents#Endpoint Profiling

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice