exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 409 discussion

Actual exam question from Cisco's 350-401
Question #: 409
Topic #: 1
[All 350-401 Questions]

A customer wants to provide wireless access to contractors using a guest portal on Cisco ISE. The portal is also used by employees. A solution is implemented, but contractors receive a certificate error when they attempt to access the portal. Employees can access the portal without any errors.
Which change must be implemented to allow the contractors and employees to access the portal?

  • A. Install a trusted third-party certificate on the Cisco ISE.
  • B. Install an internal CA signed certificate on the Cisco ISE.
  • C. Install a trusted third-party certificate on the contractor devices.
  • D. Install an internal CA signed certificate on the contractor devices.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zpacket
Highly Voted 2 years, 7 months ago
Selected Answer: A
"It is recommended to use the Company Internal CA for Admin and EAP certificates, and a publicly-signed certificate for Guest/Sponsor/Hotspot/etc portals. The reason is that if a user or guest comes onto the network and ISE portal uses a privately-signed certificate for the Guest Portal, they get certificate errors or potentially have their browser block them from the portal page. To avoid all that, use a publicly-signed certificate for Portal use to ensure better user experience". Thanks @jj970us for the reference - https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html
upvoted 16 times
AndreasThornus
2 years, 5 months ago
I agree with this one. Why would you go to the effort of making a web portal available, only to have to install certificates on contractor devices you don't manage.
upvoted 5 times
...
slacker_at_work
1 year, 3 months ago
I approve this message as the solely truth, when ever you see this question in the exam think twice; would a "trusted third-party certificate on the Cisco ISE" not be better ?
upvoted 2 times
...
...
Normanby
Highly Voted 2 years, 6 months ago
Selected Answer: A
A is the 'best' solution , but I have done 'D' in the past - faster and cheaper :)
upvoted 7 times
...
Zeruz
Most Recent 7 months, 1 week ago
Good luck trying even to convince all contractors users to install a certificate into their devices. I double dare you.
upvoted 1 times
...
[Removed]
11 months, 2 weeks ago
Selected Answer: A
It´s A By installing a certificate from a trusted third-party CA on the Cisco ISE, we ensure that the certificate is recognized and trusted by most devices, including those used by contractors, without requiring any changes on the contractor devices themselves.
upvoted 1 times
...
Shri_Fcb10
1 year ago
Selected Answer: A
Here's why this solution is appropriate: Trusted by All: A trusted third-party certificate (from a well-known Certificate Authority) is universally trusted by most devices, including those of contractors and employees. Avoiding Manual Configuration: By using a third-party certificate, you avoid the need to manually install certificates on each contractor's device, which is impractical and not user-friendly. Seamless Experience: This approach provides a seamless experience for all users, as their devices will recognize and trust the certificate without any additional configuration. Thus, installing a trusted third-party certificate on Cisco ISE ensures that all users, regardless of their device configuration, can access the portal without encountering certificate errors.
upvoted 2 times
...
Glaudus50
1 year, 5 months ago
Selected Answer: A
A is the answer. The certificate needs to be trusted by contractor's computers, which will not trust the internal CA of the company.
upvoted 2 times
...
rami_mma
2 years, 1 month ago
Selected Answer: A
A is correct
upvoted 2 times
...
mikhailov_ivan90
2 years, 3 months ago
Selected Answer: D
tricky question with several meaning from Cisco again, looks like they don't want to check your knowledge but want to make you get mistake and pay for the exam again (capitan obvious). So, they didn't mention in the question anything about kind of contractor devices , right? it can be anything , even something very old without the last chain of "green" public CAs, right? In this case there is only one option - it's adding the ISE cert to trusted on on all devices. I'd choose D.
upvoted 6 times
HarwinderSekhon
1 year, 11 months ago
That is why cisco exams except CCNA are loosing popularity.
upvoted 3 times
danman32
1 year, 9 months ago
Not to mention the widening scope of trivia knowledge for the exams and the cost
upvoted 1 times
...
...
...
PeterTheCheater
2 years, 5 months ago
Selected Answer: D
If the issue is not happening with employees devices means that the certificate on ISE is signed by an Internal CA recognised by employees devices Installing a third-party certificate on ISE has a cost, while installing a internal CA signed certificate on contractor devices does not. And since they are your contractors,i.e. work for you, you can do this certificate installation. It is not like providing public wifi to citizens. I think in this case the right answer is D.
upvoted 2 times
danman32
1 year, 9 months ago
Contractors could be anyone, not just someone you have effectively as an employee.
upvoted 1 times
...
...
Larp
2 years, 7 months ago
Selected Answer: A
A is the answer. The certificate needs to be trusted by contractor's computers, which will not trust the internal CA of the company.
upvoted 2 times
...
onkel_andi
2 years, 7 months ago
Selected Answer: A
Contractors would get a certificate error if the answer would be B) because they don't trust the CA from the Company. So answer is A)
upvoted 3 times
...
Caledonia
2 years, 8 months ago
Selected Answer: A
It is A
upvoted 3 times
...
jj970us
2 years, 8 months ago
Selected Answer: A
Reference: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215621-tls-ssl-certificates-in-ise.html
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago