Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium
A company is implementing a new BYOD policy and needs to ensure that personal devices can access corporate resources securely, but only after passing a security posture assessment. Which Cisco solution is best suited to provide this dynamic access control based on endpoint compliance?
- ACisco Umbrella
- BCisco Identity Services Engine (ISE)
- CCisco Firepower Threat Defense (FTD)
- DCisco Secure Network Analytics (Stealthwatch)
Show answer & explanationAnswer & explanation
Correct answer: B. Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) is designed for network access control (NAC), providing authentication, authorization, and accounting (AAA) services. It can assess endpoint posture and dynamically assign network access based on compliance, making it ideal for BYOD scenarios.
Why the other options are wrong
- A. Umbrella provides DNS-layer security and secure web gateway functions, not endpoint posture assessment for network access.
- C. FTD is primarily a firewall/IPS solution, not designed for endpoint posture assessment and dynamic network access control.
- D. Stealthwatch focuses on network visibility and anomaly detection, not endpoint compliance-based access control.
Cisco Identity Services Engine (ISE)
A network access control (NAC) solution from Cisco that provides centralized authentication, authorization, and accounting (AAA) for wired, wireless, and VPN connections. It can enforce security policies based on device type, user identity, and security posture.
- Performs endpoint profiling and posture assessment.
- Enforces dynamic access policies (e.g., VLAN assignment, ACLs).
- Integrates with other security solutions.
- Critical for BYOD and guest access management.
Memory trick: ISE is the bouncer checking IDs and attitudes at the club door.