350-701 · Question #695
An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what…
The correct answer is A. Configure ISE and the WLC for quest redirection and services using a self-registered portal. To provide temporary dynamic guest access with visibility using Cisco ISE and WLC, configuring a self-registered guest portal allows users to create accounts, granting access while maintaining an audit trail of their identity.
Question
An engineer is configuring guest WLAN access using Cisco ISE and the Cisco WLC. Which action temporarily gives guest endpoints access dynamically while maintaining visibility into who or what connecting?
Options
- AConfigure ISE and the WLC for quest redirection and services using a self-registered portal.
- BModify the WLC configuration to allow any endpoint to access an internet-only VLAN.
- CConfigure ISE and the WLC for guest redirection and services using a hotspot portal.
- DModify the WLC configuration to require local WLC logins for the authentication prompts.
How the community answered
(56 responses)- A75% (42)
- B4% (2)
- C7% (4)
- D14% (8)
Why each option
To provide temporary dynamic guest access with visibility using Cisco ISE and WLC, configuring a self-registered guest portal allows users to create accounts, granting access while maintaining an audit trail of their identity.
A self-registered guest portal, when configured with Cisco ISE and WLC, dynamically grants temporary access to guests who create their own accounts, which provides visibility into who is connecting by requiring them to input their personal information during the registration process.
Allowing any endpoint to access an internet-only VLAN provides access but offers no mechanism to identify individual users or maintain visibility, failing the requirement for knowing "who or what connecting."
A hotspot portal typically grants internet access without requiring users to register with unique credentials, which reduces the level of individual user visibility compared to a self-registered portal.
Requiring local WLC logins for authentication prompts is not scalable for guest access and does not facilitate dynamic self-registration or provide a self-service mechanism for temporary access.
Concept tested: Cisco ISE Guest Self-Registration Portal
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01010.html
Topics
Community Discussion
No community discussion yet for this question.