DevNet Associate (DEVASC) v1.0Cisco Platforms and DevelopmentHard
A network engineer wants to automate the process of adding and deleting users from a specific security group on their Cisco Identity Services Engine (ISE) deployment. They need to interact with ISE using a RESTful API. Which API family within Cisco ISE would be used for managing user identities and groups?
- AExternal RESTful API (ERS)
- BMonitoring API
- CANC API
- DPxGrid API
Show answer & explanationAnswer & explanation
Correct answer: A. External RESTful API (ERS)
The External RESTful Services (ERS) API in Cisco ISE is specifically designed for programmatic create, read, update, and delete (CRUD) operations on ISE configurations, including identity groups, users, policies, and network devices. This is the correct API for managing users and groups.
Why the other options are wrong
- B. Monitoring API is for retrieving operational data and session information, not configuration changes.
- C. ANC (Adaptive Network Control) API is for dynamic policy actions (e.g., quarantine), not for managing user identities themselves.
- D. PxGrid API is for contextual information exchange and policy enforcement, not direct configuration management of users/groups.
Cisco ISE ERS API
The Cisco Identity Services Engine (ISE) External RESTful Services (ERS) API provides a programmatic interface for CRUD operations on ISE configuration objects, such as users, endpoints, identity groups, and network devices.
- Used for configuration management on ISE.
- Supports standard RESTful HTTP methods (GET, POST, PUT, DELETE).
- Requires specific ERS administrative privileges.
- Enables automation of ISE provisioning.
Memory trick: ISE has many doors, but ERS is for changing the guest list and rules.