300-435 Question 175
Single answerYou are deploying Cisco Software-Defined Access (SDA) in an enterprise network. During the setup, you want to ensure that user devices are dynamically assigned to the correct VLANs and policies based on their identity. Which key SDA component is responsible for this functionality?
- A
Cisco DNA Center
- B
Identity Services Engine (ISE)
- C
Fabric Control Plane Node
- D
Fabric Border Node
Show answer and explanation
Correct answer: B
Explanation
In a Cisco SDA deployment, Identity Services Engine (ISE) plays a key role in enabling dynamic segmentation by authenticating users and devices and then assigning them to the appropriate VLANs and policies based on their identity. This functionality ensures that network access is secure and policy-driven, which is a fundamental aspect of SDA.
- A. Incorrect.
Cisco DNA Center provides centralized management, automation, and analytics in SDA but does not handle the dynamic assignment of VLANs and policies based on user identity.
- B. Correct.
Identity Services Engine (ISE) is responsible for user authentication, identity-based policy enforcement, and dynamic VLAN assignment in SDA. It is a critical component for enabling dynamic segmentation.
- C. Incorrect.
Fabric Control Plane Node handles the mapping of endpoints to virtual networks and tracks the location of devices within the fabric but does not handle identity-based policy assignment.
- D. Incorrect.
Fabric Border Node serves as the on-ramp/off-ramp for traffic entering or leaving the SDA fabric and does not handle identity-based VLAN and policy assignments.