Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

An organization is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security policy dictates that all remote users must use multi-factor authentication (MFA) and their devices must pass a posture assessment before establishing a VPN tunnel. Which two Cisco ISE components are crucial for enforcing these requirements during the VPN connection process?

  1. AMFA Server and Data Loss Prevention (DLP) Module
  2. BAuthenticator and Accounting Service
  3. CPolicy Enforcement Point (PEP) and Policy Information Point (PIP)
  4. DPolicy Decision Point (PDP) and Posture Policy Service
Show answer & explanation

Correct answer: D. Policy Decision Point (PDP) and Posture Policy Service

The Policy Decision Point (PDP) within ISE is responsible for evaluating the authentication (including MFA) and authorization policies. The Posture Policy Service is the specific ISE component that assesses the endpoint's compliance (posture) against defined security requirements before granting access. Both are critical for this scenario.

Why the other options are wrong

  • A. MFA server is external or integrated, but not an ISE component name. DLP is unrelated to VPN posture/MFA.
  • B. Authenticator (e.g., VPN headend) is the enforcement point. Accounting logs actions, but doesn't make policy decisions or perform posture assessment.
  • C. PEP enforces policies, but PDP makes the decision. PIP provides contextual information, but isn't the decision-maker or posture assessor.

Cisco ISE for VPN Access

Cisco Identity Services Engine (ISE) integrates with VPN solutions (like Cisco Secure Firewall VPN) to provide centralized authentication, authorization, and posture assessment for remote access.

  • Acts as the RADIUS server for VPN authentication.
  • Performs posture assessment on VPN clients (e.g., via Cisco Secure Client).
  • Enforces granular access based on user identity and device compliance.

Memory trick: For VPN, ISE decides 'who's in' and 'is their device clean'.

More Endpoint Security and Secure Network Access questions