300-430 Question 290
Single answerA network administrator is configuring Cisco Identity Services Engine (ISE) to provide secure wireless network access for employees. The goal is to allow only corporate-issued devices to connect to the enterprise wireless network. Which feature of ISE should be implemented to achieve this requirement?
- A
Posture Assessment
- B
Device Profiling
- C
Guest Access Portal
- D
MAC Filtering
Show answer and explanation
Correct answer: B
Explanation
Device Profiling is the correct feature to implement in Cisco ISE for identifying and allowing only corporate-issued devices to connect to the enterprise wireless network. It uses various techniques, such as analyzing DHCP or RADIUS attributes, to classify devices and enforce access policies based on their profile.
- A. Incorrect.
Posture Assessment is used to verify a device's compliance with security policies, such as antivirus or patch levels. While useful, it does not determine whether a device is corporate-issued.
- B. Correct.
Device Profiling allows ISE to identify the type of device connecting to the network through characteristics like MAC address, DHCP signatures, or other network protocols. This enables the identification of corporate-issued devices.
- C. Incorrect.
Guest Access Portal is designed to manage guest users accessing the network and is unrelated to identifying corporate devices.
- D. Incorrect.
MAC Filtering can restrict specific devices based on MAC addresses, but it is not scalable or effective for identifying corporate-issued devices in a dynamic environment.