Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-715 Exam - Topic 12 Question 84 Discussion

The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectivelyrestrict network access for this endpoint?
C) Add MAC address to the endpoint quarantine list.
A) Configure access control list on network switches to block traffic.
B) Create authentication policy to force reauthentication.
D) Implement authentication policy to deny access.

Cisco 300-715 Exam - Topic 12 Question 84 Discussion

Actual exam question for Cisco's 300-715 exam
Question #: 84
Topic #: 12
[All 300-715 Questions]

The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectively

restrict network access for this endpoint?

Show Suggested Answer Hide Answer
Suggested Answer: C

Cisco ISE provides a feature called Adaptive Network Control (ANC) that allows administrators to apply policies to endpoints based on their behavior or status1. One of the ANC policies is Quarantine, which restricts network access for an endpoint by assigning it to a limited-access VLAN or applying an access control list (ACL) on the switch port2. To use the Quarantine policy, the administrator must add the MAC address of the rogue endpoint to the endpoint quarantine list in ISE2. This will trigger a change of authorization (CoA) for the endpoint and apply the Quarantine policy. The other options are not effective for restricting network access for a rogue endpoint, as they do not use the ANC feature of ISE.


Contribute your Thoughts:

0/2000 characters
Tyra
9 months ago
Not sure about B, reauthentication might not be enough in this case.
upvoted 0 times
...
Chuck
9 months ago
Agreed with C, that’s the standard procedure for rogue devices.
upvoted 0 times
...
Davida
10 months ago
Wait, can you really just block it with an ACL? Seems too simple.
upvoted 0 times
...
Dulce
10 months ago
I think D is the better choice, just deny access outright.
upvoted 0 times
...
Nancey
10 months ago
Definitely option C, quarantine that MAC address!
upvoted 0 times
...
Danica
10 months ago
I vaguely recall that forcing reauthentication could help, but I’m not sure if it actually restricts access like the question asks.
upvoted 0 times
...
Aide
11 months ago
I feel like blocking traffic with an ACL could work, but I’m not confident it’s the most effective method in Cisco ISE.
upvoted 0 times
...
Carol
11 months ago
I think we practiced a similar question where we had to deny access through an authentication policy. That might be what they're looking for in this case.
upvoted 0 times
...
Nathan
11 months ago
I remember we discussed how adding a MAC address to the quarantine list could be a direct way to restrict access, but I'm not entirely sure if that's the best option here.
upvoted 0 times
...
Marcos
11 months ago
Easy peasy, the answer is C. Quarantining the rogue endpoint by adding its MAC address to the list is the most straightforward way to restrict its network access within Cisco ISE.
upvoted 0 times
...
Jerilyn
11 months ago
I'm a little confused on the best approach here. Should we be looking at authentication policies or access control lists instead of just quarantining the endpoint? I want to make sure I fully understand the right solution before answering.
upvoted 0 times
...
Aileen
11 months ago
Okay, I've got this. The key is to use Cisco ISE to effectively restrict the rogue endpoint. That means we need to add the MAC address to the quarantine list - option C is the way to go.
upvoted 0 times
...
Lashon
11 months ago
Hmm, I'm a bit unsure about this one. I'm trying to remember if there are other options besides just quarantining the endpoint. Maybe something with reauthentication or an access control list could work too?
upvoted 0 times
...
Scarlet
11 months ago
I think the answer is C - adding the MAC address to the endpoint quarantine list. That seems like the most direct way to restrict network access for that rogue endpoint.
upvoted 0 times
...
Lezlie
11 months ago
Okay, let's see here. A War Room is used for coordinating and managing security incidents, so the capabilities should be related to that. I'm pretty confident I can narrow it down to the right two options.
upvoted 0 times
...
Krissy
11 months ago
This seems like a tricky one. I'll need to think through the 802.1X deployment process and how to identify failed authentications without disrupting the endpoint.
upvoted 0 times
...
Arletta
11 months ago
Okay, let's see here. The question says I need to mount the OS disk offline to troubleshoot the boot issue. I think option A, "az vm repair create", might be the way to go, but I'll double-check the other options just to be sure.
upvoted 0 times
...
Gracia
2 years ago
I think creating authentication policy to force reauthentication might also be necessary to ensure security.
upvoted 0 times
...
Sanda
2 years ago
It could work, but adding the MAC address to the quarantine list is a more targeted approach.
upvoted 0 times
...
Alayna
2 years ago
But wouldn't configuring access control list on network switches to block traffic be more effective?
upvoted 0 times
...
Loreta
2 years ago
I agree with Sanda, that way we can restrict network access for that rogue endpoint.
upvoted 0 times
...
Sanda
2 years ago
I think we should add the MAC address to the endpoint quarantine list.
upvoted 0 times
...
Aleta
2 years ago
Configuring access control list on network switches to block traffic might be a good solution too.
upvoted 0 times
...
Antonio
2 years ago
I think creating an authentication policy to force reauthentication could also be effective.
upvoted 0 times
...
Harrison
2 years ago
I disagree, I believe we should implement an authentication policy to deny access.
upvoted 0 times
...
Alaine
2 years ago
I think the best option is to add the MAC address to the endpoint quarantine list.
upvoted 0 times
...
Janna
2 years ago
Whoa, hold on there, Kyoko! 'Shut it down quickly' - that's a bit extreme, don't you think? Let's not get carried away and start denying access without due process. Option C is still the safest bet in my opinion.
upvoted 0 times
...
Rex
2 years ago
Haha, I'd love to see the look on the rogue user's face when they try to connect and get denied! Option D is definitely my pick.
upvoted 0 times
...
Theola
2 years ago
I don't know, I'm not sure quarantining the device is the only solution. Maybe we could also consider forcing a reauthentication, as option B suggests.
upvoted 0 times
...
Kyoko
2 years ago
I'm not convinced. If it's truly a rogue endpoint, we shouldn't waste time with reauthentication. We need to shut it down quickly before it causes any damage. Quarantine is the way to go.
upvoted 0 times
...
Carla
2 years ago
Yeah, I was leaning towards C as well. Adding the MAC address to the quarantine list sounds like the most effective way to restrict access for this rogue endpoint.
upvoted 0 times
Britt
2 years ago
By taking this action, the security team can effectively restrict access for the rogue endpoint.
upvoted 0 times
...
Hyun
2 years ago
Adding the MAC address to the quarantine list is a necessary step in network security.
upvoted 0 times
...
Tonette
2 years ago
Agreed, it's a proactive measure to protect the network from any potential threats.
upvoted 0 times
...
Willodean
2 years ago
Once the MAC address is added to the quarantine list, the network should be more secure.
upvoted 0 times
...
Paz
2 years ago
It's important to isolate the rogue endpoint to prevent any potential security risks.
upvoted 0 times
...
Helga
2 years ago
Definitely, adding it to the quarantine list will prevent further network access.
upvoted 0 times
...
Evangelina
2 years ago
C) Add MAC address to the endpoint quarantine list.
upvoted 0 times
...
...
Willow
2 years ago
That's a good point, Jennie. Option B, creating an authentication policy to force reauthentication, could be a better approach in some cases. It gives the user a chance to authenticate properly.
upvoted 0 times
Deja
2 years ago
Configuring access control list on network switches to block traffic could also prevent any unauthorized access.
upvoted 0 times
...
Lashon
2 years ago
But wouldn't adding the MAC address to the endpoint quarantine list also help isolate the rogue endpoint?
upvoted 0 times
...
Layla
2 years ago
I think option B, creating an authentication policy to force reauthentication, is the best approach.
upvoted 0 times
...
...
Chanel
2 years ago
Hmm, this question seems straightforward enough. I'm thinking either C or D would be the best approach here.
upvoted 0 times
...
Jennie
2 years ago
I'm not so sure about that. What if the rogue endpoint belongs to a legitimate user who forgot to connect through the proper channels? Wouldn't it be better to force reauthentication instead of just quarantining it?
upvoted 0 times
...
Portia
2 years ago
I agree with Rebecka. Option C is the way to go. Quarantining the rogue MAC address is the most straightforward and efficient way to handle this situation within Cisco ISE.
upvoted 0 times
...
Rebecka
2 years ago
This question seems to be testing our knowledge of Cisco ISE and how to manage rogue endpoints. I think the correct answer is C) Add MAC address to the endpoint quarantine list. This will effectively restrict the rogue endpoint from accessing the network without having to configure access control lists or authentication policies.
upvoted 0 times
...

Save Cancel