exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 292 discussion

Actual exam question from Cisco's 350-701
Question #: 292
Topic #: 1
[All 350-701 Questions]


Refer to the exhibit. A Cisco ISE administrator adds a new switch to an 802. 1X deployment and has difficulty with some endpoints gaining access. Most PCs and
IP phones can connect and authenticate using their machine certificate credentials; however, printers and video cameras cannot. Based on the interface configuration provided, what must be done to get these devices onto the network using Cisco ISE for authentication and authorization while maintaining security controls?

  • A. Configure authentication event fail retry 2 action authorize vlan 41 on the interface.
  • B. Add mab to the interface configuration.
  • C. Enable insecure protocols within Cisco ISE in the allowed protocols configuration.
  • D. Change the default policy in Cisco ISE to allow all devices not using machine authentication.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Korndal
10 months ago
Selected Answer: B
100% B. MAB is not enabled on the port, so only 802.1x enabled devices can get onto the network (if they pass authentication and authorization)
upvoted 1 times
...
[Removed]
1 year, 3 months ago
It's interesting that they even have C as an option. Because if you authenticate MAB to Windows NPS, you have to add MD5-EAP manually to NPS as it is considered insecure.
upvoted 1 times
...
Darkestblood
1 year, 6 months ago
Selected Answer: B
B is correct.
upvoted 1 times
...
[Removed]
1 year, 9 months ago
Selected Answer: B
B is correct.
upvoted 1 times
...
Jessie45785
2 years ago
Selected Answer: B
I am working with ISE since 1.x version and there never was anything like default authentication and authorization policy - MAB is te way to go
upvoted 3 times
...
Vlad_Is_Love_ua
2 years, 2 months ago
Selected Answer: B
B is correct
upvoted 4 times
...
luisseijuro
2 years, 2 months ago
Selected Answer: B
B is correct https://community.cisco.com/t5/network-access-control/problems-with-connecting-printers-via-mab/td-p/3528002
upvoted 2 times
...
Anonymous983475
2 years, 3 months ago
Selected Answer: B
Cameras, Printers, and devices not having user interaction don't have dot1x capabilities. MAB is used for these kind of devices.
upvoted 3 times
...
Medusa8
2 years, 4 months ago
Selected Answer: B
Should be MAB, My answer is B.
upvoted 2 times
...
Emlia1
2 years, 5 months ago
Probably B
upvoted 1 times
...
sis_net_sec
2 years, 6 months ago
Selected Answer: B
https://sirius-cyber.net/2020/06/08/cisco-ise-mac-authentication-bypass-mab/
upvoted 1 times
...
Trovech
2 years, 6 months ago
I think mab is the only way to authenticate printers and cameras, I stand to be corrected. To me B is the answer.
upvoted 1 times
...
NikoNiko
2 years, 9 months ago
B is correct - MAB. Printers, cameras, video conference devices, etc.. either don't have 802.1X supplicant or if they have it, it could be difficult to manage. So these devices are usually authenticated and authorized by Mac Authentication Bypass (MAB) + Profiling on ISE (profiling is classification of the devices by type, function, etc... ISE recognizes devices like cameras / Cisco Phones / printers / ... and these attributes can be used in the ISE policy to apply desired authorization to the endpoints)
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago