Q24Profiler
What provides Cisco ISE with an option to scan endpoints for vulnerabilities?
← → navigate · a answer
Community votes
Discussion · 13
4
Answer B is definitely the correct answer ... you can clearly see the option in the Authorization profile tab :
Authorization Profile
* Name
Description
* Access Type
Network Device Profile
Service Template
Track Movement
Passive Identity Tracking
DACL Name
ACL (Filter-ID)
Security Group
VLAN
Voice Domain Permission
Web Redirection (CWA, MDM, NSP, CPP)
Display Certificates Renewal Message
Static IP/Host name/FQDN
Suppress Profiler CoA for endpoints in Logical Profile
Auto Smart Port
[Assess Vulnerabilities
Adapter Instance
Trigger scan if the time since last scan is greater than
Enter value in hours (1-9999)
Assess periodically using above interval]
3
Authorization Policy calls the chosen authorization profile. The latter performs the endpoint scanning. Correct answer is B.
2
Looking in my lab, I think the answer should actually be Authorization Policy since you build out the values in the policy / conditions studio. The authorization profile doesn't make any mention of assessing vulnerabilities. Anyone else thinking the same?
2
B is the correct answer
Configure Authorization Profile
The authorization profile in Cisco ISE now includes an option to scan endpoints for vulnerabilities. You can choose to run the scan periodically and also specify the time interval for these scans. After you define the authorization profile, you can apply it to an existing authorization policy rule or create a new authorization policy rule.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010100.html
B 2
Selected Answer: B
It's a Common Task in the Authorization Profile. The Authorization Policy is where you invoke the Authorization Profile.
B 2
Selected Answer: B
The authorization profile in Cisco ISE now has an option to scan endpoints for vulnerabilities. You can choose to run the scan periodically and also set the time interval for these scans. After you define the authorization profile, you can apply it to an existing authorization policy rule or create a new authorization policy rule.
B 2
Selected Answer: B
authorization profile
B 2
Selected Answer: B
B-authorization profile-- agreed, this is where the option is set
2
this Q showed up in my exam today.
2
my choice is B
The authorization profile in Cisco ISE now has an option to scan endpoints for vulnerabilities. (Cisco Identity Services Engine Administrator Guide, Release 2.7)
1
I was wrong, there is an Assess Vulnerabilities option in the profile to do TC-NAC for endpoints.
D 1
Selected Answer: D
Correct answer is D
The authorization policy is where you set flags for endpoint vulnerabilities, profiles only compile the endpoint-specific data in the identity store. The auth policy directly scans and "advises" the PAN of any possible vulnerabilities.
1
The authorization profile in Cisco ISE now includes an option for scanning endpoints for vulnerabilities. You can set the scan to run periodically and also define the time interval for those scans. Once you create the authorization profile, you can apply it to an existing authorization policy rule or make a new authorization policy rule.