Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-715 Exam - Topic 12 Question 85 Discussion

An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?
B) Add the device to all PSN nodes in the deployment.
A) Use a third-party certificate on the network device.
C) Renew the expired certificate on one of the PSN.
D) Configure an authorization profile for the end users.

Cisco 300-715 Exam - Topic 12 Question 85 Discussion

Actual exam question for Cisco's 300-715 exam
Question #: 85
Topic #: 12
[All 300-715 Questions]

An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?

Show Suggested Answer Hide Answer
Suggested Answer: B

When using separate PSNs for different sites, the network device must be added to all PSN nodes in the deployment, so that the device can communicate with the appropriate PSN based on the location of the user1. If the device is not added to all PSN nodes, the user may encounter an EAP-TLS authentication failure when moving between sites, as the device may not be able to reach the PSN that issued the certificate2. The other options are not relevant for this scenario, as they do not address the issue of PSN communication.


Contribute your Thoughts:

0/2000 characters
Stefania
9 months ago
I doubt it's just a simple config issue, could be something deeper.
upvoted 0 times
...
Brett
9 months ago
Wait, isn't it weird that they got that error just moving sites?
upvoted 0 times
...
Altha
10 months ago
Definitely not A, third-party certs can complicate things.
upvoted 0 times
...
Domonique
10 months ago
I think B is the right move here, gotta add the device to all PSNs.
upvoted 0 times
...
Shayne
10 months ago
Sounds like a certificate issue, maybe option C?
upvoted 0 times
...
Son
10 months ago
I think renewing an expired certificate could definitely cause authentication failures, but I’m not entirely sure if that’s the only thing we need to check.
upvoted 0 times
...
Malcolm
11 months ago
I’m a bit confused about the authorization profile option. I don’t recall it being directly related to EAP-TLS failures, but it might be worth considering.
upvoted 0 times
...
Juliann
11 months ago
I feel like we had a similar practice question where adding devices to PSN nodes was the solution. Could that be the answer here too?
upvoted 0 times
...
Iluminada
11 months ago
I remember we discussed EAP-TLS issues in class, and I think it might be related to certificates. But I'm not sure if it's about renewing or using a third-party one.
upvoted 0 times
...
Timothy
11 months ago
Ah, I see now. The issue is likely with the certificates, so we need to either use a third-party certificate or renew the expired certificate on one of the PSN nodes. I'll weigh the options carefully.
upvoted 0 times
...
Amber
11 months ago
Hmm, I'm a bit confused. Is the problem with the certificates on the network devices or the PSN nodes? I'll need to review the details more carefully.
upvoted 0 times
...
Tish
11 months ago
This one seems tricky, but I think I can figure it out. The key is to focus on the issue with the EAP-TLS authentication failure when moving between remote sites.
upvoted 0 times
...
Kate
11 months ago
Okay, I've got an idea. Since the user is moving between remote sites, the configuration must be applied across the entire deployment, not just on one PSN. I'm leaning towards option B.
upvoted 0 times
...
Keshia
11 months ago
Okay, I think I've got a strategy. I'll start by calculating the number of faces that need to be captured, then I'll look at the resolution options and see which one meets the 80 pixels per face requirement. I just need to make sure I'm doing the math correctly.
upvoted 0 times
...
Tresa
11 months ago
Whoa, this is a lot of details to keep track of. I'm a bit confused on how to approach this and calculate the planned value. Might need to review my notes on earned value management.
upvoted 0 times
...
Herschel
2 years ago
Interesting point, Using a third-party certificate could also be a valid solution to the problem.
upvoted 0 times
...
Brice
2 years ago
I disagree. I believe the solution is to use a third-party certificate on the network device.
upvoted 0 times
...
Tammara
2 years ago
I agree with It makes sense to update the certificate to resolve the authentication issue.
upvoted 0 times
...
Herschel
2 years ago
I think the correct configuration is to renew the expired certificate on one of the PSN.
upvoted 0 times
...
Craig
2 years ago
Adding the device to all PSN nodes might help in resolving the authentication issue.
upvoted 0 times
...
Chi
2 years ago
That could be a solution. Or maybe we should add the device to all PSN nodes?
upvoted 0 times
...
Oretha
2 years ago
Should we use a third-party certificate on the network device?
upvoted 0 times
...
Craig
2 years ago
I think the issue might be related to the EAP-TLS authentication.
upvoted 0 times
Basilia
2 years ago
C) Renew the expired certificate on one of the PSN.
upvoted 0 times
...
Octavio
2 years ago
B) Add the device to all PSN nodes in the deployment.
upvoted 0 times
...
...

Save Cancel