A managed service is rolling out advanced wireless infrastructure to support an expanding organization with diverse device types. The implementation requires integration of dynamic endpoint profiling for secure access and device classification. According to the baseline deployment with ISE policy sets, the engineering group must enforce access parameters based on device category rules. Which configuration action must be taken to fulfill the initiative?
Dynamic endpoint profiling in Cisco wireless networks is used to classify devices based on type, behavior, and attributes, enabling policy enforcement that adapts to device posture. In a deployment integrated with Cisco ISE, profiling groups are created to define rules and categories for device types such as smartphones, laptops, printers, and IoT devices. These profiling groups allow the wireless controller to map devices to the correct ISE policy sets dynamically, ensuring that security policies, VLAN assignments, and access controls are applied according to the device profile. Option A (device-type groups) is a generic categorization that does not fully leverage ISE dynamic profiling capabilities. Option C (user ID groups) focuses on user identity rather than device characteristics. Option D (endpoint group mapping) is typically applied after device profiling and classification, but initial enforcement requires creating profiling groups. By configuring profiling groups, the IT team ensures that the network can classify endpoints automatically, enforce access policies consistently, and integrate with ISE for context-aware security and compliance monitoring. Reference topics: Wireless Monitoring and Management --- Dynamic endpoint profiling, Cisco ISE policy integration, profiling groups, device classification for secure access.
German
19 hours agoLauryn
6 days agoEarleen
11 days agoBrianne
16 days agoDaniela
21 days agoDonette
27 days agoThurman
1 month agoGeoffrey
1 month agoGiovanna
1 month agoTawna
2 months agoKerry
2 months ago