Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy

A security engineer is designing a secure network access solution for a new branch office. The solution must provide granular access control based on user roles and device posture, and integrate with existing Active Directory for user authentication. Which Cisco technology is best suited to meet these requirements?

  1. ACisco Firepower Threat Defense (FTD)
  2. BCisco DNA Center
  3. CCisco Identity Services Engine (ISE)
  4. DCisco Umbrella
Show answer & explanation

Correct answer: C. Cisco Identity Services Engine (ISE)

Cisco Identity Services Engine (ISE) is a robust solution for network access control that can integrate with Active Directory, enforce policies based on user roles and device posture, and provide granular access control.

Why the other options are wrong

  • A. Cisco Firepower Threat Defense (FTD) is primarily a next-generation firewall and intrusion prevention system, not designed for granular access control based on user roles and device posture.
  • B. Cisco DNA Center is a network management and automation platform, not directly involved in granular access control policy enforcement.
  • D. Cisco Umbrella is a cloud security platform focusing on DNS-layer security and secure web gateway, not network access control.

Cisco Identity Services Engine (ISE)

Cisco Identity Services Engine (ISE) is a security policy management platform that enables organizations to enforce compliance, enhance infrastructure security, and streamline service operations.

  • Centralized network access policy enforcement
  • Authentication, Authorization, and Accounting (AAA) services
  • Supports user roles and device posture assessment
  • Integrates with various network devices and directories

Memory trick: ISE is the 'Identity Sentinel' for network gates.

More Endpoint Security and Secure Network Access questions