exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 243 discussion

Actual exam question from Cisco's 350-701
Question #: 243
Topic #: 1
[All 350-701 Questions]

An engineer wants to automatically assign endpoints that have a specific OUI into a new endpoint group. Which probe must be enabled for this type of profiling to work?

  • A. SNMP
  • B. NMAP
  • C. DHCP
  • D. NetFlow
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jeeves69
Highly Voted 4 years, 1 month ago
The answer is C, through DHCP Profiling. The OUI is part of the MAC address, which can be learned from the dhcp-client-identifier option 61.
upvoted 34 times
semi1750
3 years, 1 month ago
I agree. NMAP scan is based on IP, any information collected during scan will be discarded if MAC-IP binding doesn't exist According to ISE profile design guide, "The dhcp-client-identifier typically provides the MAC address, which in turn provides the vendor OUI information through correlation from the MAC Address-OUI mapping table." under Procedure 25 Verify DHCP Probe Data https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-2096149162
upvoted 7 times
semi1750
2 years, 12 months ago
in addition to Jeeves69, It is option 60, not 61 https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-2725.pdf Vendor / OS information can be gathered from dhcp-class-identifier (60) DHCP parameter request list and DHCP class ID can be used for platform and model.
upvoted 3 times
Premium_Pils
8 months, 3 weeks ago
The dhcp-client-identifier typically provides the MAC address, which in turn provides the vendor OUI information through correlation from the MAC Address-OUI mapping table. The dhcp-class-identifier often provides a unique platform-specific attribute and in some cases provides a detailed description of the connected endpoint - in this example, MSFT 5.0 which is the value assigned to Microsoft Windows workstations. https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456
upvoted 2 times
...
...
...
044f2fc
1 year ago
And check Nmap probe to access mac ...it is done on manual scan
upvoted 1 times
044f2fc
1 year ago
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/Workflow/b_endpoint_profiling_2_4.html#reference_FD15BD65A25A4390B2A865450F938ADF
upvoted 1 times
...
...
...
nomanlands
Highly Voted 2 years, 9 months ago
Selected Answer: A
The answer is SNMP. It will work and can pull ARP tables from the network devices. In fact, page 28 in the ISE Profiling guide recommends it if Radius or DHCP probes can't be effective. An NMAP scan cannot get a MAC address. If it is on the same subnet, then it would pull the MAC from the ARP table which would then be effective. That's a big IF DHCP would missing static devices as mentioned. A Netflow probe with additional attributes of SRC_MAC and DST_MAC should also be able to work for this situation if placed properly within the networks but I'm going with SNMP as that is what is recommended in the guide.
upvoted 6 times
...
madboy2
Most Recent 1 month, 1 week ago
Selected Answer: C
Explanation: To automatically assign endpoints with a specific Organizationally Unique Identifier (OUI) into a new endpoint group, Cisco ISE needs to identify the MAC addresses of those endpoints. The DHCP probe extracts MAC addresses from DHCP request packets, allowing Cisco ISE to determine the OUI (first 24 bits of the MAC address) and categorize devices accordingly. Why not the other options? A. SNMP – Used for network device discovery, but not effective for identifying endpoint MAC addresses dynamically. B. NMAP – Performs active scanning but does not focus on OUI-based profiling. D. NetFlow – Provides traffic flow analysis, but does not extract MAC addresses from endpoint traffic.
upvoted 2 times
...
Basuso
5 months, 3 weeks ago
Selected Answer: A
Correcting myself from my answer below. According to "Probe Selection Best Practices" in the ISE Profiling Designing Guide, from the official Cisco documentation, it's SNMP.
upvoted 1 times
...
Basuso
5 months, 3 weeks ago
Selected Answer: C
I vote for C. As many before have said, the DHCP probe in Cisco ISE can capture information from DHCP requests, including the MAC address of the endpoint. The OUI is part of the MAC address and can be used to profile and categorize endpoints into specific groups based on this information.
upvoted 2 times
...
kloug
6 months, 1 week ago
Answer c
upvoted 2 times
...
luismg
7 months, 2 weeks ago
Selected Answer: C
OUI is know from the MAC address witch is located through the DHCP "DORA" process.
upvoted 2 times
...
Premium_Pils
8 months, 3 weeks ago
Selected Answer: C
https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456
upvoted 2 times
...
Korndal
10 months ago
Selected Answer: C
DHCP. This is the most used function for ISE to learn about endpoints. Since it can learn about them even if the endpoints are not in a 802.1x enabled port. NMAP is a manually/triggered. Its teoretic that some clients use static IP. Most devices use dhcp
upvoted 2 times
...
RemiK
10 months, 3 weeks ago
Selected Answer: C
More relevant about OUI stil "probe DHCP". Answer C.
upvoted 2 times
...
Rododendron2
11 months ago
Selected Answer: C
A and C will work, C for dynamic only. I just like it more. NMAP looks to me as and absolute nonsense , would work only scanning on same subnet
upvoted 2 times
...
c66bc39
11 months ago
SNMP https://community.cisco.com/t5/tkb/articleprintpage/tkb-id/4561-docs-security/article-id/6096 Procedure 11
upvoted 1 times
...
044f2fc
1 year ago
Selected Answer: D
Why not D? Check profiling probe using net flow v9 ... also dhcp on security perspective uses ip to mac binding doesn't mean it is used as a probe to get mac details..
upvoted 1 times
044f2fc
1 year ago
And check Nmap probe to access mac ...it is done on manual scan
upvoted 1 times
044f2fc
1 year ago
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/Workflow/b_endpoint_profiling_2_4.html#reference_FD15BD65A25A4390B2A865450F938ADF
upvoted 1 times
...
...
...
squirrelzzz
1 year, 1 month ago
Selected Answer: C
OUI is part of MAC Address
upvoted 1 times
...
nekkrokvlt
1 year, 7 months ago
Selected Answer: C
I vote for C As well, NMAP is layer 3.
upvoted 1 times
...
GoldFree
1 year, 8 months ago
Selected Answer: A
Probe SNMP: Key profiling attributes: · MAC Address/OUI - CDP/LLDP - ARP tables Common Endpoint Profiling Use Cases See RADIUS probe for MAC info. Valuable for any vendor that uses CDP/LLDP. For example, Cisco IP phones, cameras, access points, appliances. Polling of device ARP tables populates ISE MAC-to-IP bindings. https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456 CTRL + F to the setion: "Probe Selection Best Practices"
upvoted 2 times
...
F0rtyx40
1 year, 9 months ago
Selected Answer: A
NMAP scans for open ports and OS detection, how do you get MAC address in NMAP scans over L3? you can configure SNMP probes to start profiling and populating endpoints before enforcing MAB/802.1X IN ISE. I have done this a few times.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago