300-430 Question 292
Select 2An enterprise is deploying Cisco Identity Services Engine (ISE) to enhance network security. They want to enforce role-based access control (RBAC) for wireless users based on their department and ensure that unauthorized devices are automatically quarantined. Which two features of Cisco ISE should they configure to achieve this goal?
- A
802.1X authentication with RADIUS
- B
Posture assessment policies
- C
Profiling and endpoint classification
- D
Guest access portal
- E
Policy Sets with authorization rules
Show answer and explanation
Correct answers: A, E
Explanation
To achieve role-based access control (RBAC) and quarantine unauthorized devices, the enterprise must configure 802.1X authentication with RADIUS to authenticate users and devices and use Policy Sets with authorization rules to define role-based access permissions and quarantine actions. These features work together to enforce security policies effectively.
- A. Correct.
802.1X authentication with RADIUS is necessary to authenticate users and devices, allowing ISE to enforce role-based access control (RBAC) based on user credentials or certificates.
- B. Incorrect.
Posture assessment policies are used to evaluate the compliance of devices (e.g., checking for antivirus or patches) but do not directly enable RBAC or device quarantine.
- C. Incorrect.
Profiling and endpoint classification allow ISE to identify and categorize devices but do not enforce role-based access control or quarantine unauthorized devices.
- D. Incorrect.
Guest access portal is used to provide temporary access to guests and does not contribute to RBAC or device quarantine in this scenario.
- E. Correct.
Policy Sets with authorization rules enable ISE to enforce RBAC by defining access permissions based on user roles and can also include conditions to quarantine unauthorized devices.