ExamGecko
Question list
Search
Search

Related questions











Question 238 - 300-715 discussion

Report
Export

The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectively restrict network access for this endpoint?

A.

Configure access control list on network switches to block traffic.

Answers
A.

Configure access control list on network switches to block traffic.

B.

Create authentication policy to force reauthentication.

Answers
B.

Create authentication policy to force reauthentication.

C.

Add MAC address to the endpoint quarantine list.

Answers
C.

Add MAC address to the endpoint quarantine list.

D.

Implement authentication policy to deny access.

Answers
D.

Implement authentication policy to deny access.

Suggested answer: C

Explanation:

Cisco ISE provides a feature called Adaptive Network Control (ANC) that allows administrators to apply policies to endpoints based on their behavior or status1. One of the ANC policies is Quarantine, which restricts network access for an endpoint by assigning it to a limited-access VLAN or applying an access control list (ACL) on the switch port2. To use the Quarantine policy, the administrator must add the MAC address of the rogue endpoint to the endpoint quarantine list in ISE2. This will trigger a change of authorization (CoA) for the endpoint and apply the Quarantine policy. The other options are not effective for restricting network access for a rogue endpoint, as they do not use the ANC feature of ISE.

asked 07/10/2024
Oscar Luis Garza Ruiz
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first