nerdexam
Cisco

500-651 · Question #3

Which is a security product that was covered in the Policy and access security module?

The correct answer is B. Cisco Identity Services Engine. Cisco Identity Services Engine (ISE) is the correct answer because it is Cisco's dedicated platform for policy-based access control and identity management - the exact focus of the Policy and Access Security module. ISE handles network admission control, authenticates…

Network Security

Question

Which is a security product that was covered in the Policy and access security module?

Options

  • ACisco NFGW
  • BCisco Identity Services Engine
  • CCisco NGIPS
  • DCisco Defense Orchestrator

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    92% (22)
  • C
    4% (1)

Explanation

Cisco Identity Services Engine (ISE) is the correct answer because it is Cisco's dedicated platform for policy-based access control and identity management - the exact focus of the Policy and Access Security module. ISE handles network admission control, authenticates users/devices via 802.1X, and enforces granular access policies based on identity, device posture, and context.

Why the others are wrong:

  • A. Cisco NFGW (likely a typo for NGFW - Next-Generation Firewall): A perimeter defense/traffic filtering product, covered under network security modules, not policy/access management.
  • C. Cisco NGIPS (Next-Generation Intrusion Prevention System): A threat detection and prevention tool that inspects traffic for attacks - belongs in threat defense modules, not access policy.
  • D. Cisco Defense Orchestrator (CDO): A cloud-based management tool for orchestrating firewall and security policies across devices - more of a management/operations product than a policy-and-access identity solution.

Memory tip: Think of the word "Identity" in ISE - identity is the foundation of access control and policy enforcement. If a question mentions who gets access and what policies govern it, ISE is your answer. The other options deal with threats (NGIPS), traffic filtering (NGFW), or policy management across devices (CDO) - not identity-driven access.

Topics

#Identity Services Engine#Access Control#Policy Management#Network Access

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice