ETExamTower
Q24Profiler

What provides Cisco ISE with an option to scan endpoints for vulnerabilities?

← → navigate · a answer
Community votes
B
83% (5)
D
17% (1)
A
0% (0)
C
0% (0)
Discussion · 13
4
Answer B is definitely the correct answer ... you can clearly see the option in the Authorization profile tab : Authorization Profile * Name Description * Access Type   Network Device Profile   Service Template Track Movement Passive Identity Tracking DACL Name ACL (Filter-ID) Security Group VLAN Voice Domain Permission Web Redirection (CWA, MDM, NSP, CPP) Display Certificates Renewal Message Static IP/Host name/FQDN Suppress Profiler CoA for endpoints in Logical Profile Auto Smart Port [Assess Vulnerabilities Adapter Instance   Trigger scan if the time since last scan is greater than Enter value in hours (1-9999) Assess periodically using above interval]
3
Authorization Policy calls the chosen authorization profile. The latter performs the endpoint scanning. Correct answer is B.
2
Looking in my lab, I think the answer should actually be Authorization Policy since you build out the values in the policy / conditions studio. The authorization profile doesn't make any mention of assessing vulnerabilities. Anyone else thinking the same?
2
B is the correct answer Configure Authorization Profile The authorization profile in Cisco ISE now includes an option to scan endpoints for vulnerabilities. You can choose to run the scan periodically and also specify the time interval for these scans. After you define the authorization profile, you can apply it to an existing authorization policy rule or create a new authorization policy rule. https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010100.html
B 2
Selected Answer: B It's a Common Task in the Authorization Profile. The Authorization Policy is where you invoke the Authorization Profile.
B 2
Selected Answer: B The authorization profile in Cisco ISE now has an option to scan endpoints for vulnerabilities. You can choose to run the scan periodically and also set the time interval for these scans. After you define the authorization profile, you can apply it to an existing authorization policy rule or create a new authorization policy rule.
B 2
Selected Answer: B authorization profile
B 2
Selected Answer: B B-authorization profile-- agreed, this is where the option is set
2
this Q showed up in my exam today.
2
my choice is B The authorization profile in Cisco ISE now has an option to scan endpoints for vulnerabilities. (Cisco Identity Services Engine Administrator Guide, Release 2.7)
1
I was wrong, there is an Assess Vulnerabilities option in the profile to do TC-NAC for endpoints.
D 1
Selected Answer: D Correct answer is D The authorization policy is where you set flags for endpoint vulnerabilities, profiles only compile the endpoint-specific data in the identity store. The auth policy directly scans and "advises" the PAN of any possible vulnerabilities.
1
The authorization profile in Cisco ISE now includes an option for scanning endpoints for vulnerabilities. You can set the scan to run periodically and also define the time interval for those scans. Once you create the authorization profile, you can apply it to an existing authorization policy rule or make a new authorization policy rule.