Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 300-715 Topic 12 Question 84 Discussion

Actual exam question for Cisco's 300-715 exam
Question #: 84
Topic #: 12
[All 300-715 Questions]

The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectively

restrict network access for this endpoint?

Show Suggested Answer Hide Answer
Suggested Answer: C

Cisco ISE provides a feature called Adaptive Network Control (ANC) that allows administrators to apply policies to endpoints based on their behavior or status1. One of the ANC policies is Quarantine, which restricts network access for an endpoint by assigning it to a limited-access VLAN or applying an access control list (ACL) on the switch port2. To use the Quarantine policy, the administrator must add the MAC address of the rogue endpoint to the endpoint quarantine list in ISE2. This will trigger a change of authorization (CoA) for the endpoint and apply the Quarantine policy. The other options are not effective for restricting network access for a rogue endpoint, as they do not use the ANC feature of ISE.


Comments

Portia
3 hours ago
I agree with Rebecka. Option C is the way to go. Quarantining the rogue MAC address is the most straightforward and efficient way to handle this situation within Cisco ISE.
upvoted 0 times
...
Rebecka
2 days ago
This question seems to be testing our knowledge of Cisco ISE and how to manage rogue endpoints. I think the correct answer is C) Add MAC address to the endpoint quarantine list. This will effectively restrict the rogue endpoint from accessing the network without having to configure access control lists or authentication policies.
upvoted 0 times
...

Save Cancel