[Secure Network Access, Visibility, and Enforcement]
Which RADIUS feature provides a mechanism to change the AAA attributes of a session after it is
authenticated?
CoA stands for Change of Authorization, which is a feature that allows a RADIUS server to adjust an active client session after it is authenticated. For example, CoA can be used to reauthenticate a client, terminate a client session, or change the VLAN or group policy of a client. CoA is supported by several RADIUS vendors, including Cisco ISE. CoA is defined in RFC 5176 and uses a pushed model, where the request originates from the RADIUS server and is sent to the network device that acts as a listener. CoA requests can have two possible response codes: CoA-ACK (acknowledgment) or CoA-NAK (non-acknowledgment).Reference:=
Some possible references are:
RADIUS Change of Authorization
Change of Authorization with RADIUS (CoA) on MR Access Points
Change of Authorization with RADIUS (CoA) on MS Switches
Technical Tip: Radius COA behavior
[Security Concepts]
A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
Dynamic ARP inspection (DAI) is a security feature that validates ARP packets in a network. It intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability protects the network from certain man-in-the-middle attacks. After enabling DAI, all ports become untrusted ports.
[Endpoint Protection and Detection]
Which security solution is used for posture assessment of the endpoints in a BYOD solution?
Cisco ISE is the security solution that is used for posture assessment of the endpoints in a BYOD solution. Posture assessment allows Cisco ISE to inspect the security health of the endpoints, such as their operating system, software applications, network settings, and security software. Cisco ISE can then enforce posture policies based on the compliance status of the endpoints and grant or deny them access to the network resources. Cisco ISE supports different types of posture agents, such as AnyConnect, AnyConnect Stealth, and Temporal Agent, to monitor and remediate the endpoints. Cisco ISE also supports agentless posture for devices that cannot run an agent, such as printers, cameras, and IoT devices. Cisco ISE integrates with various third-party vendors to provide posture assessment for different endpoint platforms, such as Windows, Mac, Linux, Android, and iOS.Reference:=
Some possible references are:
Cisco Identity Services Engine Administrator Guide, Release 3.0 - Compliance
Chapter 15. Device Posture Assessment - Cisco ISE for BYOD and Secure Unified Access
Implementing and Operating Cisco Security Core Technologies (SCOR) v1.0
[Securing the Cloud]
An engineer is configuring Dropbox integration with Cisco Cloudlock. Which action must be taken before granting API access in the Dropbox admin console?
Cisco AMP for Endpoints provides next-generation protection by leveraging an endpoint protection platform (EPP) and endpoint detection and response (EDR) capabilities. EPP is a set of multifaceted prevention techniques that stop threats from compromising endpoints, such as behavioral analytics, machine learning, and signature-based methods. EDR is a set of powerful features that reduce the attack surface and remediate faster, such as advanced threat hunting, endpoint isolation, and dynamic malware analysis. Cisco AMP for Endpoints also integrates with SecureX, a built-in platform that offers extended detection and response (XDR) capabilities across multiple control points, such as network, cloud, email, and web. By combining EPP, EDR, and XDR, Cisco AMP for Endpoints delivers a comprehensive and resilient endpoint security solution that can detect, respond, and recover from sophisticated attacks.Reference:
Cisco Secure Endpoint (Formerly AMP for Endpoints) - Cisco
Cisco Secure Endpoint (Formerly AMP for Endpoints) - Cisco
Cisco Secure Endpoint (Formerly AMP for Endpoints) - Cisco
[Endpoint Protection and Detection]
A Cisco ISE engineer configures Central Web Authentication (CWA) for wireless guest access and must have the guest endpoints redirect to the guest portal for authentication and authorization. While testing the policy, the engineer notices that the device is not redirected and instead gets full guest access. What must be done for the redirect to work?
To enable CWA for wireless guest access, the ISE engineer needs to configure the following steps on the ISE server:
Create a guest portal with the desired settings and appearance.
Create an authorization profile that references the guest portal and the DACL name for the Airespace ACL configured on the WLC. The DACL name must match the name of the ACL on the WLC exactly. The authorization profile also needs to have the common tasks of Web Redirection and Web Authentication enabled.
Create an authorization policy that matches the unauthenticated devices based on the MAC address or other criteria and applies the authorization profile created in the previous step.
The DACL name is required for the WLC to apply the correct ACL to the guest endpoints and redirect them to the guest portal. Without the DACL name, the WLC will not know which ACL to use and may grant full guest access to the endpoints. Therefore, the correct answer is D.
Some possible references are:
Central Web Authentication (CWA) for guests with ISE
Understand And Troubleshoot Central Web-Authentication (CWA) In Guest Anchor Set-Up
Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Release 17.3.0 - Guest Access
John Flores
15 days agoPaul Taylor
29 days agoPatricia Anderson
2 months agoGary Walker
2 months agoOlivia Campbell
3 months agoGeorge Flores
3 months agoAnthony Jackson
3 months agoSharon Clark
4 months agoJeffrey Cook
4 months agoDorothy Peterson
4 months agoStephanie Parker
4 months agoMatthew Gonzalez
4 months agoGeorge Robinson
4 months agoElliot
5 months agoRutha
5 months agoBette
5 months agoSalena
6 months agoEarleen
6 months agoShaniqua
6 months agoWillodean
6 months agoJunita
7 months agoFelix
7 months agoDonte
7 months agoOdelia
7 months agoLorrie
7 months agoTruman
8 months agoCarmen
8 months agoEttie
8 months agoKatheryn
8 months agoRessie
9 months agoJonell
9 months agoBeula
9 months agoMattie
9 months agoShoshana
10 months agoEarleen
10 months agoMyrtie
10 months agoKeith
10 months agoEthan
11 months agoYuki
11 months agoSerina
11 months agoCelestina
11 months agoWillard
12 months agoKatie
12 months agoGregoria
1 year agoIrma
1 year agoCaitlin
1 year agoReiko
1 year agoAndree
1 year agoCarey
1 year agoCorazon
1 year agoDaron
1 year agoWynell
1 year agoRefugia
1 year agoWillow
2 years agoGregoria
2 years agoDanica
2 years agoOra
2 years agoReiko
2 years agoJohnson
2 years agoAndra
2 years agoPaola
2 years agoMila
2 years agoHillary
2 years agoValentin
2 years agoJess
2 years agoMeghann
2 years agoHarrison
2 years agoDottie
2 years agoStephaine
2 years agoCora
2 years agoKarol
2 years agoCarrol
2 years agoFanny
2 years agoNorah
2 years agoLuis
2 years agoAllene
2 years agoRegenia
2 years agoAja
2 years agoElly
2 years agoHuey
2 years agoJoseph
2 years agoYun
2 years agoDevorah
2 years agoTwana
2 years agoJacquline
2 years agoVal
2 years agoNoah
2 years agoMiles
2 years agoEverett
2 years agoLily
2 years agoEloise
2 years ago