Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A large enterprise is deploying a new network access control (NAC) solution using Cisco Identity Services Engine (ISE). The network requires that all endpoints, including corporate-owned devices and guest devices, are profiled and assigned appropriate network access policies based on their type, operating system, and installed software. Which ISE feature is primarily responsible for identifying and categorizing these endpoints?
- APosture Assessment
- BGuest Services
- CProfiling
- DAuthentication Policies
Show answer & explanationAnswer & explanation
Correct answer: C. Profiling
Cisco ISE's Profiling service is specifically designed to collect information from various network sources (DHCP, HTTP, NetFlow, etc.) to identify and categorize endpoints based on their attributes (OS, device type, manufacturer). This categorization is then used by authorization policies.
Why the other options are wrong
- A. Posture Assessment checks the compliance of an endpoint against security policies (e.g., antivirus status, patch level), it doesn't primarily identify the device type.
- B. Guest Services provides controlled access for visitors, but it relies on profiling and authorization for its functionality.
- D. Authentication Policies define how users/devices are authenticated, but don't categorize the device type itself.
Cisco ISE Profiling
A Cisco Identity Services Engine (ISE) feature that collects contextual information about connected endpoints from various network sources to identify and categorize them.
- Uses probes (e.g., DHCP, HTTP, DNS, NetFlow, NMAP) to gather data.
- Creates endpoint profiles based on attributes like OS, device type, manufacturer.
- Feeds into authorization policies to assign appropriate network access.
- Essential for granular network segmentation and security.
Memory trick: ISE Processes Authenticate, Profile, Posture, Guest