700-765 · Question #81
Which two features are provided by ISE? (Choose two.)
The correct answer is A. Centralized policy management D. Network visibility. Cisco ISE (Identity Services Engine) is a policy-based access control and network visibility platform, not a firewall or DDoS mitigation tool.
Question
Which two features are provided by ISE? (Choose two.)
Options
- ACentralized policy management
- BRetrospective Security
- CDDoS attack prevention
- DNetwork visibility
- EDevice Firewalling
How the community answered
(49 responses)- A90% (44)
- B2% (1)
- C2% (1)
- E6% (3)
Why each option
Cisco ISE (Identity Services Engine) is a policy-based access control and network visibility platform, not a firewall or DDoS mitigation tool.
ISE provides centralized policy management by consolidating AAA, posture, profiling, and guest access policies into a single pane of glass, allowing administrators to define and enforce consistent access rules across the entire network from one location.
Retrospective security is a feature of Cisco Secure Endpoint (AMP), not ISE - it allows tracing a file's history after a threat is identified.
DDoS attack prevention is provided by solutions like Cisco Secure DDoS Protection or Arbor, not by ISE which focuses on identity and access control.
ISE delivers network visibility through device profiling and endpoint context collection, giving administrators real-time insight into who and what is connected to the network, including device type, OS, and compliance posture.
Device firewalling is a function of dedicated firewall products such as Cisco Secure Firewall (ASA/FTD), not ISE.
Concept tested: Cisco ISE core features and capabilities
Source: https://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html
Topics
Community Discussion
No community discussion yet for this question.