exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 207 discussion

Actual exam question from Cisco's 300-715
Question #: 207
Topic #: 1
[All 300-715 Questions]

An engineer needs to configure a new certificate template in the Cisco ISE Internal Certificate Authority to prevent BYOD devices from needing to re-enroll when their MAC address changes. Which option must be selected in the Subject Alternative Name field?

  • A. Common Name and GUID
  • B. MAC Address and GUID
  • C. Distinguished Name
  • D. Common Name
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
redpassion
Highly Voted 1 year, 5 months ago
Selected Answer: B
Prior to Cisco Identity Services Engine (ISE) 3.1, ISE provisions the certificates to endpoints with MAC Addresses seen by ISE under SAN field. Because of Randomized MAC Address, Cisco ISE sees different MAC Address when on-boarding these endpoints through BYOD flow. So, there is going to be mismatch in MAC Address imprinted under Certificate’s SAN field, seen by ISE and actual MAC Address. From Cisco Identity Services Engine (ISE) 3.1 onwards, ISE can provision the Certificates with GUID along with MAC Address under SAN field so that administrator can track the endpoint through unique parameter (GUID) from Context Visibility .
upvoted 5 times
...
Cachaman
Most Recent 2 months ago
Selected Answer: A
Correct answer A. Configure GUID for Connected MDM Servers To check if an MDM server you have already connected to Cisco ISE supports the latest Cisco ISE MDM APIs and can send GUID information, carry out the following steps: In the Cisco ISE GUI, click the Menu icon () and choose Administration > Network Resources > External MDM. In the MDM Servers window, check the check box for the MDM server you want to update, and click Edit. Click Test Connection. If the MDM server supports Cisco ISE MDM APIs Version 3, a new section called Device Identifiers is displayed. Check the check boxes for one or more of the following options that you want to enable: Cert - SAN URI, GUID Cert - CN, GUID Legacy MAC Address https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_secure_wired_access.html
upvoted 1 times
...
NullNull88
8 months, 1 week ago
from (SAN) drop-down list, choose MAC Address and GUID. To handle random and changing MAC addresses in BYOD flows, the Cisco ISE provisioning service generates a GUID value for Windows, iOS, and Android endpoints. If you have configured the Subject Alternative Name (SAN) of your certificate to include the GUID value to handle random MAC addresses in a BYOD flow, choose Subject - Common Name as the certificate attribute for identity validation when you configure a Certificate Authentication Profile to authenticate AD users.
upvoted 3 times
...
NullNull88
8 months, 1 week ago
B isn't correct,.. why look for the MAC? We don't know what it is,.. it can change we don't want to use this combination we only want GUID but that is not a choice here
upvoted 1 times
NullNull88
8 months, 1 week ago
Answer is A
upvoted 1 times
...
...
XBfoundX
11 months, 2 weeks ago
I will go for B based on this: Cisco ISE 3.1 can now look up devices with GUID As explained in the release notes for Cisco ISE 3.1, this new version employs a different approach to locating devices on a network. Admins can configure ISE to use a globally unique identifier (GUID), to identify devices and interface about them with an MDM service. The Jamf Pro integration for Cisco ISE now allows for all communications between the two solutions about devices to use GUID instead of MAC addresses. This new device identification method also solves for environments where dongles and multiple network interfaces would cause lookups to fail. https://www.jamf.com/blog/cisco-ise-31-mdm-solutions/
upvoted 3 times
...
IETF1
1 year ago
B. MAC Address and GUID ( ISE 3.1 and above)
upvoted 2 times
...
ccamar
1 year, 4 months ago
Could it be option C? Official Cert GUide SISE : The ISE GUI also allows you to customize the Subject Alternative Name (SAN) field, which is meant to carry a number of different attributes, each designed to aid in the identification of the certificate. You can add the following customizations for the SAN field: â– â–  DNS Name: This is the FQDN of the ISE node. If the certificate will be a wildcard certificate, be sure to specify the wildcard notation (*). â– â–  IP Address: This is the IP address of the ISE node associated with the certificate. â– â–  Uniform Resource Name: This is the URI associated with the certificate. â– â–  Directory Name: This is a string representation of the distinguished name (DN). DNs are defined in RFC 2253.
upvoted 1 times
...
Frankie_Boy
1 year, 9 months ago
Selected Answer: B
B is right: "Subject Alternative Name (SAN): Currently, only value available is the MAC Address." Currently, only value available is the MAC Address."
upvoted 3 times
...
kornalt
1 year, 9 months ago
Selected Answer: B
Should be B
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago