350-401 exam dumps

350-401 practice question 293 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 293

Select 2

An organization has deployed Cisco Identity Services Engine (ISE) to enforce endpoint security policies. The network administrator wants to ensure that only compliant endpoints (e.g., devices with updated antivirus software, enabled firewalls, and the latest patches) can access the corporate network. Which two mechanisms can the administrator use to achieve this goal?

  1. A

    Posture assessment using Cisco AnyConnect Secure Mobility Client

  2. B

    MAC address filtering on network switches

  3. C

    802.1X authentication with dynamic VLAN assignment

  4. D

    Guest portal redirection for endpoint compliance checks

  5. E

    Certificate-based authentication with endpoint posture validation

Show answer and explanation

Correct answers: A, E

Explanation

To enforce endpoint security policies, Cisco ISE can leverage posture assessment mechanisms, such as those integrated into AnyConnect, to evaluate endpoint compliance against security policies. Additionally, certificate-based authentication with posture validation adds a layer of authentication and ensures that only compliant devices gain network access. These approaches align with Cisco's best practices for securing enterprise networks.

  • A. Correct.

    Posture assessment using Cisco AnyConnect Secure Mobility Client allows the Cisco ISE to evaluate endpoint compliance by checking for security attributes such as antivirus status, patches, and firewall settings, making it a valid method for enforcing endpoint security policies.

  • B. Incorrect.

    MAC address filtering on network switches is a basic security mechanism that verifies device identity based on MAC addresses but does not check endpoint compliance, so it is not suitable for ensuring security policies are met.

  • C. Incorrect.

    802.1X authentication with dynamic VLAN assignment provides user or device authentication and network segmentation but does not inherently validate the endpoint's security posture, so it is not sufficient for compliance enforcement.

  • D. Incorrect.

    Guest portal redirection is typically used for guest access management and does not perform posture checks on endpoints connecting to the corporate network, making it unsuitable for this scenario.

  • E. Correct.

    Certificate-based authentication with endpoint posture validation combines strong identity authentication with the ability to check endpoint compliance, helping enforce endpoint security policies effectively.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam