Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-715 Exam - Topic 11 Question 65 Discussion

An engineer is configuring Cisco ISE policies to support MAB for devices that do not have 802.1X capabilities. The engineer is configuring new endpoint identity groups as conditions to be used in the AuthZ policies, but noticed that the endpoints are not hitting the correct policies. What must be done in order to get the devices into the right policies?
D) Identify the non 802.1X supported device types and create custom profiles for them to profile into.
A) Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.
B) Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.
C) Add an identity policy to dynamically add the IP address of the devices to their endpoint identity groups.

Cisco 300-715 Exam - Topic 11 Question 65 Discussion

Actual exam question for Cisco's 300-715 exam
Question #: 65
Topic #: 11
[All 300-715 Questions]

An engineer is configuring Cisco ISE policies to support MAB for devices that do not have 802.1X capabilities. The engineer is configuring new endpoint identity groups as conditions to be used in the AuthZ policies, but noticed that the endpoints are not hitting the correct policies. What must be done in order to get the devices into the right policies?

Show Suggested Answer Hide Answer
Suggested Answer: D, E

Contribute your Thoughts:

0/2000 characters
Callie
10 months ago
I disagree, A is the most straightforward solution here.
upvoted 0 times
...
In
10 months ago
Wait, D? Custom profiles for non-802.1X devices? That's new to me!
upvoted 0 times
...
Brittni
10 months ago
C seems a bit off, IP addresses won't help if they can't do 802.1X.
upvoted 0 times
...
Keva
11 months ago
I think B could work too, partial access is better than none.
upvoted 0 times
...
Latrice
11 months ago
Definitely A, you need to manually add those MAC addresses.
upvoted 0 times
...
Nana
11 months ago
Adding IP addresses dynamically sounds familiar, but I can't recall if that's specifically for MAB or just for general endpoint management.
upvoted 0 times
...
Brandon
11 months ago
I feel like we practiced a question similar to this where we had to identify device types and create custom profiles. That might be relevant here.
upvoted 0 times
...
Alison
11 months ago
I think creating an AuthZ policy for Unknown devices could help, but I’m not entirely confident if that’s the best approach for MAB.
upvoted 0 times
...
Lashawn
11 months ago
I remember we talked about manually adding MAC addresses to endpoint ID groups, but I'm not sure if that's the only step needed.
upvoted 0 times
...
Kayleigh
11 months ago
Okay, I think I have an idea. I'll go with using a BPEL Process Manager sensor to collect the variable data and send it to a JMS queue.
upvoted 0 times
...
Sharee
11 months ago
I was thinking about option C, but it feels tricky since Kinesis Data Analytics is usually more associated with real-time, not just historical insights.
upvoted 0 times
...
Caprice
11 months ago
I'm pretty sure the answer is utility service, since that's the service model most associated with process abstraction and orchestration patterns.
upvoted 0 times
...
Timmy
11 months ago
I'm a bit confused. Do I need to calculate the total amount Rhona needs to deposit today to cover all these future expenses? Seems complex.
upvoted 0 times
...
Horace
1 year ago
I'm just gonna go with D and hope I don't get any of those 'non-802.1X' devices in my network. That's like trying to configure a VCR these days.
upvoted 0 times
Dusti
1 year ago
User3: Agreed, custom profiles will definitely help with those devices.
upvoted 0 times
...
Fletcher
1 year ago
User2: Yeah, that sounds like the best option to avoid any issues.
upvoted 0 times
...
Rhea
1 year ago
User1: I think D is the way to go, custom profiles for non-802.1X devices.
upvoted 0 times
...
...
Gladis
1 year ago
Dynamically adding IP addresses to endpoint groups? That's straight out of the 90s, man. This is Cisco ISE, we're all about that MAB now!
upvoted 0 times
Miss
1 year ago
D) Identify the non 802.1X supported device types and create custom profiles for them to profile into.
upvoted 0 times
...
Abel
1 year ago
B) Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.
upvoted 0 times
...
Twana
1 year ago
A) Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.
upvoted 0 times
...
Florinda
1 year ago
D) Identify the non 802.1X supported device types and create custom profiles for them to profile into.
upvoted 0 times
...
Veronique
1 year ago
B) Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.
upvoted 0 times
...
Leigha
1 year ago
A) Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.
upvoted 0 times
...
...
Vi
1 year ago
Wait, what? Unknown devices get partial network access? That sounds like a security nightmare! I'm gonna go with option D, it's the safest bet.
upvoted 0 times
Louvenia
1 year ago
I agree, it's important to properly identify and profile those devices to ensure network security.
upvoted 0 times
...
Lillian
1 year ago
Option D is a good choice, creating custom profiles for non 802.1X supported devices is a secure approach.
upvoted 0 times
...
...
Dana
1 year ago
Is this a trick question? I mean, why not just manually add the MAC addresses to the endpoint ID groups? Seems like the easiest solution.
upvoted 0 times
Lottie
1 year ago
D) Identify the non 802.1X supported device types and create custom profiles for them to profile into.
upvoted 0 times
...
Mariko
1 year ago
C) Add an identity policy to dynamically add the IP address of the devices to their endpoint identity groups.
upvoted 0 times
...
Danica
1 year ago
B) Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.
upvoted 0 times
...
Cheryll
1 year ago
A) Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.
upvoted 0 times
...
...
Carissa
1 year ago
Ah, finally a MAB-related question! I've been preparing for this. I think option D is the way to go - identifying the non-802.1X devices and creating custom profiles for them. That way, they'll get the right policies applied.
upvoted 0 times
...
Lucy
1 year ago
Hmm, I see your point. Maybe we should consider both options and see which one works best in practice.
upvoted 0 times
...
Kathryn
1 year ago
I disagree, I believe the correct answer is B) Create an AuthZ policy for Unknown devices.
upvoted 0 times
...
Lucy
1 year ago
I think the answer is A) Manually add the MAC addresses of the devices to endpoint ID groups.
upvoted 0 times
...

Save Cancel