ETExamTower
Q62Secure Network Access, Visibility, and EnforcementMultiple answers

A network engineer must configure a Cisco ISE server for external authentication against Active Directory. What must be considered regarding the authentication requirements? *(Choose two.)*

Select 2 answers.
← → navigate · a answer
Community votes
D
47% (14)
E
40% (12)
A
7% (2)
B
3% (1)
C
3% (1)
Discussion · 23
5
Radius is between ISE and the NAD (network access device), not DC
4
While ISE account must be admin, Don't need Admin account in Active directory to perform join operation. AD supports mschapv2 for machine and user authentication. LDAP must be permitted between ISE and AD domain controller. Ans is DE
D, E 4
Selected Answer: DE ISE only authenticates the user; it does not JOIN machines to the domain, so no admin account is needed. LDAP is used for communication with the Microsoft AD
4
ISE only uses RADIUS to talk with the clients, and not with the AD
D, E 3
Selected Answer: DE I would go with D,E as well according to this doc: https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1079999 "MS-CHAPv2—Cisco ISE supports user and machine authentication against Active Directory using EAP-MSCHAPv2." "If there is a firewall between Cisco ISE and Active Directory, certain ports need to be opened to allow Cisco ISE to communicate with Active Directory. Ensure that the following default ports are open: LDAP 389 UDP (...amongst others)"
D, E 3
Selected Answer: DE Agree with the others on D and E. I wasn't sure whether B could be an option, but after more research you don't need to be a domain admin to join a workstation/server to a domain. However this documentation from Cisco states "Ensure you have Active Directory Domain Admin credentials, required to make changes to any of the AD domain configurations." https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html It would be disappointing if B was one of the two correct answers.
D, E 2
Selected Answer: DE A. RADIUS communication must be permitted between the ISE server and the domain controller. - NOT TRUE - this is only between Authenticator (switch / AP ) and Authentication Server (ie. ISE) B. The ISE account must be a domain administrator in Active Directory to perform JOIN operations. - NOT TRUE - it just needs a regular account, no DC Admin privileges are needed - such account is usually called service account C. Active Directory only supports user authentication by using MSCHAPv2. - NOT TURE - many others are supported as already mentioned below
D, E 2
Selected Answer: DE A is wrong , msrpc/kerberos/ldap only needed B is wrong, ISE account (superuser) is different than domain admin. C is wrong , mschapv2 is used for user or machine auth (so E is correct) D is correct. E is correct check the 3 tables in cisco doc (AD-ISE integration steps) : https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html
D, E 2
Selected Answer: DE https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1079999 Microsoft Active Directory Cisco ISE uses Active Directory as an external identity source to access resources like users, machines, groups, and attributes. You can configure Cisco ISE to authenticate users and machines. Answer D is correct ^^ MS-CHAPv2—Cisco ISE supports user and machine authentication against Active Directory using EAP-MSCHAPv2 Answer E is correct ^^
2
They should really let you delete posts when you make mistakes (because you're tired of staring at all these questions!!). To continue - I messed up above and should have said that E is correct based on those two statements in that doc. The other answer is D and it's found here: https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_94BE6ABB85BC47C8AEC29EF8D286E6E4 Under the table heading: Network Ports That Must Be Open for Communication The table says LDAP TCP/UDP port 389 must communicate with DC Disregard the comment about C.
B, C 1
Selected Answer: BC B and C is the correct answer
D, E 1
Selected Answer: DE https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01101.pdf
1
I think it's b and e.... B bcz we need to create&set admin group ... E bcz c is not correct. Ad supports many user ways ntlm etc...I would go for b & e
D, E 1
Selected Answer: DE I prefer DE
D, E 1
Selected Answer: DE Answer: DE
1
DE makes more sense
A, D 1
Selected Answer: AD A & D Cisco ISE needs Radius and LDAP to communicate with Active Directory.
1
Active Directory supports several authentication protocols, including MSCHAPv2, Kerberos, and NTLM.
D, E 1
Selected Answer: DE https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_new_chapter_0100001.html#ID467
A, D 1
Selected Answer: AD I am going with A & D: A. RADIUS communication must be allowed between the ISE server and the domain controller: Cisco ISE can use RADIUS as one of the protocols to communicate with the Active Directory domain controller for user authentication. E Does not sound right because Active Directory supports both user and machine authentication using various authentication protocols, not only MSCHAPv2. agree with achille5 4 months, 2 weeks ago Active Directory supports several authentication protocols, including MSCHAPv2, Kerberos, and NTLM.
1
****That last one should say C is correct****
1
AFAIK ISE account is not an admin account, Its a computer account that we allow login to. The account used to join ISE to AD needs special permissions and most of the time it's an admin user
D, E 1
Selected Answer: DE Cisco's official protocol support matrix confirms that Active Directory supports MSCHAPv2