Free Cisco 300-715 SISE Actual Exam Questions - Question 13 Discussion
An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected. Which service should be used to accomplish this task?
It’s A since profiling is the key service for dynamically identifying endpoints, which is the first step before any protection like posture enforcement happens. Without accurate profiling, posture can’t work effectively.
It’s D because posture goes beyond just identifying devices; it checks their security status and enforces policies, which fits the need for both dynamic ID and protected access.
It’s A because profiling automatically detects and classifies devices on the network, which is essential for dynamic identification before applying any access restrictions.
D imo, since posture not only identifies but also enforces compliance to protect access, making it more comprehensive than just profiling.
A, since profiling is key for identifying endpoints before enforcing access controls.
Option A, since profiling dynamically identifies devices before applying any access controls.
Guessing A on this one. Profiling is all about discovering and categorizing devices as they connect, which matches the dynamic identification part. While posture checks the health status, it assumes you already know what device it is. Since the question highlights dynamically identifying endpoints first, profiling fits better. Protection might come from other policies, but without identifying the endpoint type, you can't enforce anything properly. So profiling seems like the core service needed here.
A imo, since the question emphasizes dynamic identification, profiling is the main service for discovering and classifying endpoints. Enforcement might be separate, but profiling is the first step here.
Maybe A, since profiling actively detects and classifies devices dynamically, which is key for identification. The protection part might be handled elsewhere, but this is the core for endpoint ID.
D imo, because while profiling identifies devices, it doesn’t enforce access policies or protect endpoints by checking their compliance state. Posture assessment actually makes sure the device meets security requirements before granting access, so it covers both identification and protection. Profiling alone seems incomplete for the full task described here.
A/D? Profiling (A) definitely nails the dynamic identification part by recognizing devices on the network. But the question also mentions ensuring endpoint access is protected, which means just knowing what the device is might not be enough. Posture (D) checks if the device meets security policies before granting access, adding that protection layer. So while profiling gets you the ID, posture ensures compliant and safe access. I’d go with D for the full package here.
A/D? Profiling (A) identifies devices well, but posture (D) adds the protection layer by ensuring compliance. Since the question mentions both identification and protection, posture seems necessary too.
Makes sense that profiling fits here since it helps identify devices dynamically. So, I’d say A.