300-435 Question 174
Single answerA network engineer is tasked with integrating Cisco DNA Center with a Software-Defined Access (SDA) fabric to simplify network management and enforce security policies. The engineer needs to configure the SDA fabric to support micro-segmentation for different user groups. Which component of the SDA architecture is primarily responsible for enabling this functionality?
- A
Control Plane Node
- B
Fabric Edge Node
- C
Identity Services Engine (ISE)
- D
Fabric Border Node
Show answer and explanation
Correct answer: C
Explanation
Cisco Identity Services Engine (ISE) plays a critical role in the SDA architecture by enabling micro-segmentation through group-based policies. It integrates with Cisco DNA Center to enforce security and segmentation based on user or device identity, ensuring that different user groups can be isolated or allowed to communicate as per the defined policies. Other components, such as Control Plane Nodes, Fabric Edge Nodes, and Fabric Border Nodes, have distinct roles but do not handle policy enforcement for segmentation.
- A. Incorrect.
The Control Plane Node is responsible for managing endpoint-to-location mappings using LISP, but it does not enforce micro-segmentation policies.
- B. Incorrect.
The Fabric Edge Node provides connectivity for endpoints to the SDA fabric but does not handle micro-segmentation policy enforcement.
- C. Correct.
Identity Services Engine (ISE) is responsible for policy enforcement and segmentation in SDA. It provides user identity and group-based policy mapping, which is essential for enabling micro-segmentation.
- D. Incorrect.
The Fabric Border Node handles external connectivity between the SDA fabric and external networks but is not involved in segmentation or policy enforcement within the fabric.