exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 209 discussion

Actual exam question from Cisco's 300-715
Question #: 209
Topic #: 1
[All 300-715 Questions]

A security administrator is using Cisco ISE to create a BYOD onboarding solution for all employees who use personal devices on the corporate network. The administrator generates a Certificate Signing Request and signs the request using an external Certificate Authority server. Which certificate usage option must be selected when importing the certificate into ISE?

  • A. RADIUS
  • B. DLTS
  • C. Portal
  • D. Admin
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rhylos
Highly Voted 1 year ago
Selected Answer: C
C - Portal. The certificate that resides on the PSN isn’t issued to the BYOD devices. It is used when setting up the trusted communication between the PSN and the device. Not only will you need to apply It to the portals but you will also need it for EAP https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_0110.html#reference_3CE11FC8D0F14A3285E37D197B5646A3 Certificate Usage When you add or import a certificate in to Cisco ISE, you should specify the purpose for which the certificate is to be used: · Admin: For internode communication and authenticating the Admin portal · EAP: For TLS-based EAP authentication · RADIUS DTLS: For RADIUS DTLS server authentication · Portal: For communicating with all Cisco ISE end-user portals · xGrid: For communicating with the pxGrid controller
upvoted 5 times
...
Leogxn
Most Recent 10 months, 1 week ago
Selected Answer: C
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ISE_26_admin_guide/b_ISE_admin_26_byod.html#task_CF674614ECA44F929F859A7229B7AF6D Add Certificates to the Device Portal If you do not want to use the default certificates, you can add a valid certificate and assign it to a certificate group tag. The default certificate group tag used for all end-user web portals is Default Portal Certificate Group.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...