300-425 Question 211
Single answerAn enterprise wants to onboard employee devices securely using native supplicant provisioning through Cisco Identity Services Engine (ISE). During the process, employees are required to connect to a temporary open SSID before their device is configured and connected to the secure SSID. What is the most important step to ensure successful native supplicant provisioning?
- A
Ensure the temporary open SSID is configured for WebAuth redirection to ISE.
- B
Pre-install the AnyConnect Secure Mobility Client on all employee devices.
- C
Configure the secure SSID with WPA3 Enterprise and EAP-TLS.
- D
Enable DHCP server functionality on the secure SSID.
Show answer and explanation
Correct answer: A
Explanation
In a native supplicant provisioning workflow using Cisco ISE, the temporary open SSID plays a critical role in redirecting users to the onboarding portal hosted on ISE. Without WebAuth redirection configured, the onboarding process cannot start. Other steps, such as configuring the secure SSID or DHCP, are important but are not directly tied to the native supplicant provisioning process.
- A. Correct.
Correct. Native supplicant provisioning requires the temporary SSID to redirect users to the ISE portal for configuration and onboarding.
- B. Incorrect.
Incorrect. While AnyConnect can be used in some scenarios, it is not a requirement for native supplicant provisioning via ISE.
- C. Incorrect.
Incorrect. Although WPA3 Enterprise and EAP-TLS are secure configurations, they are unrelated to the initial provisioning process.
- D. Incorrect.
Incorrect. DHCP is essential for IP addressing, but enabling it on the secure SSID is not specific to the provisioning process.