A Cisco ISE administrator must restrict specific endpoints from accessing the network while in closed mode. The requirement is to have Cisco ISE centrally store the endpoints to restrict access from. What must be done to accomplish this task?
A.
Create a profiling policy for each endpoint with the cdpCacheDeviceId attribute.
B.
Create a logical profile for each device's profile policy and block that via authorization policies.
C.
Add each MAC address manually to a blocklist identity group and create a policy denying access.
D.
Add each IP address to a policy denying access.
The correct answer is - Add each MAC address manually to a blocklist identity group and create a policy denying access.
To accomplish this task, the Cisco ISE administrator must follow these steps:
Create a blocklist identity group.
Add each MAC address of the endpoints that must be restricted from accessing the network to the blocklist identity group.
Create a policy that denies access to the blocklist identity group.
Apply the policy to the network access devices.
Blocklist" identity group is a feature that allows you to define a group of identities (users or endpoints) that should be denied network access based on specific criteria. can be configured based on various criteria, such as usernames, MAC addresses, IP addresses, device attributes, or other identity attributes. You can manually add identities to the Blocklist group or dynamically populate the group using various identity sources, such as Active Directory, LDAP, or RADIUS.
C is more appropriate-- a logical profile must be matched based n a profiler result. there is no assurance that the devices will get profiled properly or at all. A mac address is something you get right away and is absolute.
B is a bit organized way but alternate could be C.
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.300-715 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
NullNull88
8 months, 3 weeks agodenverfly
1 year, 5 months agorhylos
1 year, 5 months agotheorgin
1 year, 5 months agoTHEODORABLE
1 year, 6 months agoaHash
2 years agokingsalah1982
2 years ago