Q9Web Auth and Guest Services
Which two values does the binary comparison function compare in authentication based on Active Directory?
← → navigate · a answer
Community votes
Discussion · 13
7
Correct answer is A (if you need to choose only one answer).
Correct answer is A and D (if you need to choose two answers).
A 5
Selected Answer: A
The answer looks to be "A". See this line from the official book: "A binary comparison takes the public certificate used by the user or device attempting access and performs a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA)."
4
A is correct answer.
Always perform binary comparison—This option always performs the binary comparison of client certificate to certificate on account in identity store (Active Directory or LDAP).
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html
2
Answer is D. Can confirm in my LAB.
2
I think the key word here is "values". From the ISE admin guide: Basic certificate checking does not require an identity source. If you want binary comparison checking for the certificates, you must select an identity source. If you choose Active Directory as an identity source, subject and common name and subject alternative name (all values) can be used to look up a user.
1
the other answer correct is B: MS-CHAPv2 provided machine credentials and credentials stored in Active Directory
1
It has to be D. If option A were true, certificate templates on ADCS can be set not to store the generated certificates in AD, in which case ISE would not be able to do the authentication since it cannot find the referenced certificate.
1
Correct answer is D (if asked to choose 1)
Correct answers are D, A (if asked to choose 2)
https://imgur.com/O050NJF
1
A - A binary comparison
takes the public certificate used by the user or device attempting access and performs
a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA). This
setting is configured in the CAP by choosing the Perform Binary Certificate Comparison
with Certificate Retrieved from LDAP or Active Directory option and selecting which LDAP
or AD store will contain the copies of the public certificates.
A 1
Selected Answer: A
A is my choice-- the only binary comparison I can recall is the option on a certificate authentication profile--and that is optional
C 1
Selected Answer: C
The binary comparison function in authentication based on Active Directory compares the user-presented password hash and a hash stored in Active Directory.
The user types their password, which is then hashed with a one-way function. The hash is then sent to the authentication server, which compares it against the hash stored in Active Directory. If the hashes match, the user is authenticated.
The other options are incorrect.
A user-presented certificate is not used in authentication that is based on Active Directory.
MS-CHAPv2 is a challenge-response protocol that is used to authenticate machines, not users.
The subject alternative name and the common name are fields in a certificate. They are not used in authentication that is based on Active Directory.
1
This question has two answers in the real exam.
A 1
Selected Answer: A
page 202 of OCG binary comparison
takes the public certificate used by the user or device attempting access and performs
a bit-for-bit comparison to a copy stored elsewhere (usually on the issuing CA). This
setting is configured in the CAP by choosing the Perform Binary Certificate Comparison
with Certificate Retrieved from LDAP or Active Directory option and selecting which LDAP
or AD store will contain the copies of the public certificates.