500-651 · Question #81
Which two features are provided by ISE? (Choose two.)
The correct answer is A. Centralized policy management D. Network visibility. Cisco ISE (Identity Services Engine) is a network access control (NAC) platform built around two core pillars: centralized policy management (A) - defining and enforcing who and what can access the network from a single console - and network visibility (D) - profiling devices…
Question
Which two features are provided by ISE? (Choose two.)
Options
- ACentralized policy management
- BRetrospective Security
- CDDoS attack prevention
- DNetwork visibility
- EDevice Firewalling
How the community answered
(25 responses)- A88% (22)
- B4% (1)
- C8% (2)
Explanation
Cisco ISE (Identity Services Engine) is a network access control (NAC) platform built around two core pillars: centralized policy management (A) - defining and enforcing who and what can access the network from a single console - and network visibility (D) - profiling devices, authenticating users, and giving administrators a real-time view of everything connected. Retrospective Security (B) is associated with Cisco Secure Endpoint (formerly AMP), which analyzes file behavior over time after the fact. DDoS attack prevention (C) belongs to dedicated solutions like Cisco Umbrella or purpose-built scrubbing services, not ISE. Device Firewalling (E) is the domain of Cisco ASA or Firepower NGFW, not an access control/identity platform.
Memory tip: Think of ISE as the "ID badge office" of your network - it manages the rules for who gets in (policy management) and watches who's walking the halls (visibility). It doesn't fight hackers (no DDoS/firewall) and doesn't investigate past incidents (no retrospective security).
Topics
Community Discussion
No community discussion yet for this question.