Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
An organization is deploying Cisco Secure Client (formerly AnyConnect) for remote access VPN. The security team wants to ensure that only devices meeting specific security criteria, such as having a compliant operating system version, enabled firewall, and up-to-date antivirus, are allowed to establish a VPN connection. Which Cisco component should be integrated with the remote access VPN solution to perform this comprehensive posture assessment and enforce access policies?
- ACisco Adaptive Security Appliance (ASA)
- BCisco Umbrella
- CCisco Firepower Threat Defense (FTD)
- DCisco Identity Services Engine (ISE)
Show answer & explanationAnswer & explanation
Correct answer: D. Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) is the central policy management and network access control platform designed to integrate with VPN solutions like Cisco Secure Client. It performs comprehensive posture assessment of endpoints and enforces granular access policies based on the device's compliance status before granting VPN access.
Why the other options are wrong
- A. ASA can terminate VPN connections but relies on external components like ISE for advanced posture assessment.
- B. Cisco Umbrella provides DNS-layer security and secure web gateway functions, not endpoint posture assessment for VPN.
- C. FTD is a next-generation firewall with IPS capabilities, not primarily a posture assessment solution for VPN clients.
Cisco ISE for VPN Access
Cisco Identity Services Engine (ISE) integrates with VPN solutions to provide advanced posture assessment and granular access control for remote access users.
- Checks endpoint compliance before VPN connection.
- Enforces policies based on device health.
- Works with Cisco Secure Client (AnyConnect) and VPN gateways.
Memory trick: ISE is the 'bouncer' checking your 'ID' (posture) before you enter the secure VPN 'club'.