Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-430 Exam - Topic 5 Question 78 Discussion

WPA2 Enterprise with 802.1X is being used for clients to authenticate to a wireless network through a Cisco ISE server. For security reasons, the network engineer wants to ensure that only PEAP authentication is used. The engineer sent instructions to clients on how to configure the supplicants, but the ISE logs still show users authenticating using EAP-FAST. Which action ensures that access to the network is restricted for these users unless the correct authentication mechanism is configured?
A) Enable AAA override on the SSID, gather the usernames of these users, and disable the RADIUS accounts until the devices are correctly configured.
B) Enable AAA override on the SSID and configure an ACL on the WLC that allows access to users with IP addresses from a specific subnet.
C) Enable AAA override on the SSID and configure an access policy in Cisco ISE that denies access to the list of MACs that have used EAP-FAST.
D) Enable AAA override on the SSID and configure an access policy in Cisco ISE that allows access only when the EAP authentication method is PEAP.

Cisco 300-430 Exam - Topic 5 Question 78 Discussion

Actual exam question for Cisco's 300-430 exam
Question #: 78
Topic #: 5
[All 300-430 Questions]

WPA2 Enterprise with 802.1X is being used for clients to authenticate to a wireless network through a Cisco ISE server. For security reasons, the network engineer wants to ensure that only PEAP authentication is used. The engineer sent instructions to clients on how to configure the supplicants, but the ISE logs still show users authenticating using EAP-FAST. Which action ensures that access to the network is restricted for these users unless the correct authentication mechanism is configured?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Ruth
9 months ago
Definitely need to enforce PEAP only, it's more secure!
upvoted 0 times
...
Nichelle
9 months ago
Option C seems too restrictive, might lock out legit users.
upvoted 0 times
...
Simona
10 months ago
Surprised they didn't just block EAP-FAST outright!
upvoted 0 times
...
Raymon
10 months ago
But what if users are still using EAP-FAST?
upvoted 0 times
...
Stevie
10 months ago
I think option D is the way to go!
upvoted 0 times
...
Richelle
10 months ago
I feel like option C could be a good choice, but I’m not entirely clear on how the access policy would deny those MACs effectively.
upvoted 0 times
...
Amie
11 months ago
I think enabling an ACL could work, but I’m uncertain if it’s the best way to enforce PEAP only.
upvoted 0 times
...
Casie
11 months ago
This question feels similar to one we practiced where we had to configure access policies in ISE. I think option D makes the most sense.
upvoted 0 times
...
Paulene
11 months ago
I remember studying about AAA override, but I'm not sure if it directly restricts EAP-FAST users.
upvoted 0 times
...
Valda
11 months ago
This looks like a good opportunity to use the access policy feature in Cisco ISE. By enabling AAA override and then configuring an ISE policy to only allow PEAP authentication, we can effectively block the users who are still using EAP-FAST without having to disable their accounts. Seems like the most efficient way to address this issue.
upvoted 0 times
...
Yvonne
11 months ago
I'm not entirely sure about the best approach here. Should we disable the RADIUS accounts for the users who are still using EAP-FAST, or is there a way to restrict their access without impacting their accounts? I want to make sure we find a solution that doesn't cause too much disruption for the users.
upvoted 0 times
...
Corrinne
11 months ago
Okay, I've got this. The question is asking us to restrict access for users who are still using EAP-FAST, even though the instructions were to use PEAP. By enabling AAA override and then creating an access policy in ISE to only allow PEAP, we can ensure those users won't be able to connect until they update their supplicant settings.
upvoted 0 times
...
Casandra
11 months ago
Hmm, I'm a bit confused about the different EAP authentication methods and how they work with Cisco ISE. I'll need to review the details on PEAP and EAP-FAST to make sure I understand the differences and how to properly configure the network.
upvoted 0 times
...
Theodora
11 months ago
This seems like a straightforward question about configuring the wireless network to only allow PEAP authentication. I think the key is to use the AAA override option and then set up an access policy in Cisco ISE to restrict access based on the authentication method.
upvoted 0 times
...
Keshia
1 year ago
Hold up, are we sure the users aren't just trying to sneak in some EAP-FAST action? Maybe they're just feeling nostalgic for the good old days. Either way, D is the answer, and I'm not going to judge their authentication preferences.
upvoted 0 times
Kaycee
1 year ago
User 3: Let's stick to the security guidelines and go with option D.
upvoted 0 times
...
Josphine
1 year ago
User 2: D is the answer, we need to ensure only PEAP is used.
upvoted 0 times
...
Bernadine
1 year ago
User 1: Maybe they just miss EAP-FAST, who knows.
upvoted 0 times
...
...
Amos
1 year ago
Yeah, D is definitely the way to go. No need to get all Big Brother on those users. Just set it up so they can only connect with PEAP, and let them figure it out. Easy peasy!
upvoted 0 times
Stephane
1 year ago
User 3: Definitely, no need to go overboard with disabling accounts or blocking MACs.
upvoted 0 times
...
Beula
1 year ago
User 2: Yeah, that way they'll have to configure it correctly to connect.
upvoted 0 times
...
Altha
1 year ago
User 1: I agree, D is the best option. Just make it so they can only use PEAP.
upvoted 0 times
...
...
Kiley
1 year ago
Haha, I like the way you think! Denying access based on MAC addresses is a clever idea, but I bet those users would just start spoofing their MACs. D is probably the better long-term solution.
upvoted 0 times
Tamekia
1 year ago
Cherilyn: Definitely, sticking with PEAP authentication is key.
upvoted 0 times
...
Myra
1 year ago
User 3: D seems like the most secure option in the long run.
upvoted 0 times
...
Cherilyn
1 year ago
User 2: Yeah, it's a constant cat-and-mouse game with security.
upvoted 0 times
...
Kassandra
1 year ago
User 1: I agree, MAC address spoofing is a real concern.
upvoted 0 times
...
...
Tonette
1 year ago
I'm not sure, but A also sounds like a good option to gather usernames and disable accounts until they are correctly configured.
upvoted 0 times
...
France
1 year ago
Hmm, I'm not sure about that. Disabling RADIUS accounts or configuring an ACL on the WLC based on IP addresses seems a bit too heavy-handed. D looks like the more targeted and secure approach.
upvoted 0 times
Timmy
1 year ago
User 2: Yeah, it seems like the most secure option to ensure only PEAP authentication is used.
upvoted 0 times
...
Corrina
1 year ago
User 1: I think option D is the way to go.
upvoted 0 times
...
...
Billy
1 year ago
I agree with Gail, D seems like the most logical choice to ensure only PEAP authentication is used.
upvoted 0 times
...
Dominque
1 year ago
I think the correct answer is D. Enabling AAA override and configuring an access policy in Cisco ISE to allow access only when the EAP authentication method is PEAP seems like the most straightforward way to ensure that users can only use the desired authentication mechanism.
upvoted 0 times
...
Gail
1 year ago
I think the answer is D, because it specifically mentions restricting access based on the authentication method.
upvoted 0 times
...

Save Cancel