nerdexam
Cisco

500-651 · Question #81

Which two features are provided by ISE? (Choose two.)

The correct answer is A. Centralized policy management D. Network visibility. Cisco ISE (Identity Services Engine) is a network access control (NAC) platform built around two core pillars: centralized policy management (A) - defining and enforcing who and what can access the network from a single console - and network visibility (D) - profiling devices…

Network Security

Question

Which two features are provided by ISE? (Choose two.)

Options

  • ACentralized policy management
  • BRetrospective Security
  • CDDoS attack prevention
  • DNetwork visibility
  • EDevice Firewalling

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    4% (1)
  • C
    8% (2)

Explanation

Cisco ISE (Identity Services Engine) is a network access control (NAC) platform built around two core pillars: centralized policy management (A) - defining and enforcing who and what can access the network from a single console - and network visibility (D) - profiling devices, authenticating users, and giving administrators a real-time view of everything connected. Retrospective Security (B) is associated with Cisco Secure Endpoint (formerly AMP), which analyzes file behavior over time after the fact. DDoS attack prevention (C) belongs to dedicated solutions like Cisco Umbrella or purpose-built scrubbing services, not ISE. Device Firewalling (E) is the domain of Cisco ASA or Firepower NGFW, not an access control/identity platform.

Memory tip: Think of ISE as the "ID badge office" of your network - it manages the rules for who gets in (policy management) and watches who's walking the halls (visibility). It doesn't fight hackers (no DDoS/firewall) and doesn't investigate past incidents (no retrospective security).

Topics

#ISE (Identity Services Engine)#Centralized Policy Management#Network Visibility#Network Access Control

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice