exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 36 discussion

Actual exam question from Cisco's 300-715
Question #: 36
Topic #: 1
[All 300-715 Questions]

Which two values are compared by the binary comparison function in authentication that is based on Active Directory?

  • A. user-presented certificate and a certificate stored in Active Directory
  • B. MS-CHAPv2 provided machine credentials and credentials stored in Active Directory
  • C. user-presented password hash and a hash stored in Active Directory
  • D. subject alternative name and the common name
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pipi
Highly Voted 3 years, 7 months ago
Correct answer is A (if you need to choose only one answer). Correct answer is A and D (if you need to choose two answers).
upvoted 7 times
...
YmerG
Highly Voted 1 year, 8 months ago
Selected Answer: A
The answer seems to be "A". Refer to that phrase from the official book: "A binary comparison takes the public certificate used by the user or device attempting access and performs a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA)."
upvoted 5 times
...
cybertrec
Most Recent 9 months, 4 weeks ago
Selected Answer: A
page 202 of OCG binary comparison takes the public certificate used by the user or device attempting access and performs a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA). This setting is configured in the CAP by choosing the Perform Binary Certificate Comparison with Certificate Retrieved from LDAP or Active Directory option and selecting which LDAP or AD store will contain the copies of the public certificates.
upvoted 1 times
...
ccnpsise
1 year ago
This question has two answers in the real exam.
upvoted 1 times
...
denverfly
1 year, 4 months ago
Selected Answer: C
The binary comparison function in authentication that is based on Active Directory compares the user-presented password hash and a hash stored in Active Directory. The user enters their password, which is then hashed using a one-way function. The hash is then sent to the authentication server, which compares it to the hash stored in Active Directory. If the hashes match, the user is authenticated. The other options are incorrect. A user-presented certificate is not used in authentication that is based on Active Directory. MS-CHAPv2 is a challenge-response protocol that is used to authenticate machines, not users. The subject alternative name and the common name are fields in a certificate. They are not used in authentication that is based on Active Directory.
upvoted 1 times
...
THEODORABLE
1 year, 5 months ago
Selected Answer: A
A is my choice-- the only binary comparison I can remember is the option on a certificate authentication profile--and that is optional
upvoted 1 times
...
Russ
1 year, 11 months ago
I think the crucial word here is "values". From the ISE admin guide: Basic certificate checking does not require an identity source. If you want binary comparison checking for the certificates, you must select an identity source. If you select Active Directory as an identity source, subject and common name and subject alternative name (all values) can be used to look up a user.
upvoted 2 times
...
[Removed]
1 year, 12 months ago
From the cisco learning network course - Cisco ISE will retrieve the user certificate from the active directory database and compare it, based on each octet , with the received client certificate.
upvoted 1 times
...
tururu1496
2 years ago
A - A binary comparison takes the public certificate used by the user or device attempting access and performs a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA). This setting is configured in the CAP by choosing the Perform Binary Certificate Comparison with Certificate Retrieved from LDAP or Active Directory option and selecting which LDAP or AD store will contain the copies of the public certificates.
upvoted 1 times
...
aHash
2 years ago
Correct answer is D (if asked to choose 1) Correct answers are D, A (if asked to choose 2) https://imgur.com/O050NJF
upvoted 1 times
...
user_topic
2 years, 4 months ago
Answer is D. Can confirm in my LAB.
upvoted 2 times
...
aaInman
3 years ago
A is correct answer. Always perform binary comparison—This option always performs the binary comparison of client certificate to certificate on account in identity store (Active Directory or LDAP). https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html
upvoted 4 times
...
thetaken
3 years, 2 months ago
It must be D. If option A was true, certificate templates on ADCS can be configured not to store the generated certificates in AD, in which case ISE would not be able to perform the authentication since it cannot find the referenced certificate.
upvoted 1 times
...
Kyoraku715
3 years, 9 months ago
the other answer correct is B: MS-CHAPv2 provided machine credentials and credentials stored in Active Directory
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago