Q19Secure Network Access, Visibility, and Enforcement
Which method deploys certificates and configures the supplicant on mobile devices so they can access network resources?
← → navigate · a answer
Community votes
Discussion · 20
24
The correct answer is A. BYOD onboarding
C 13
Selected Answer: C
C.
The method for deploying certificates and setting up the supplicant on mobile devices so they can access network resources is C) client provisioning.
Client provisioning is the process of pushing network settings, certificates, and other configuration details to mobile devices so they can securely connect to a network. This process includes configuring the supplicant, which is the client software that communicates with the network, to use the right authentication methods and credentials needed to access network resources.
BYOD onboarding is a process that lets personal devices connect to a corporate network, and it may include client provisioning as one of its steps. MAC authentication bypass is a method of granting network access based on the device's MAC address, without requiring any authentication credentials. Simple Certificate Enrollment Protocol (SCEP) is a protocol used for certificate management, but it is not specifically tied to configuring the supplicant or deploying network settings to mobile devices.
D 4
Selected Answer: D
I would go with D.
a) the question doesn't say anything about whether the device is corporate owned or not. So BYOD doesn't make sense.
b) authentication bypass certainly is not a method for deploying certificates.
c) client provisioning is not related to certificate deployment.
A 4
Selected Answer: A
BYOD (Bring Your Own Device) onboarding refers to securely enrolling personal mobile devices (e.g., smartphones, tablets) into a network. During onboarding, the following actions typically occur:
• Certificates are deployed on the device for secure authentication.
• The supplicant (software responsible for 802.1X authentication) is configured so it can connect to the network.
• Security policies are applied to ensure proper access control and compliance.
This method is widely used in environments where employees or users bring their own devices and need secure access to enterprise network resources
3
Thanks, ChatGPT?
3
Correct answer A:
When supporting personal devices on a corporate network, you need to protect network services and enterprise data by authenticating and authorizing users (employees, contractors, and guests) and their devices. Cisco ISE provides the tools you need to let employees securely use personal devices on a corporate network.
Guests can add their personal devices to the network by running the native supplicant provisioning (Network Setup Assistant), or by adding their devices in the My Devices portal.
Because native supplicant profiles are not available for all devices, users can use the My Devices portal to add these devices manually; or you can configure Bring Your Own Device (BYOD) rules to register them.
Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_devices_byod.html
2
do not trust chat gpt on questions like that, especially for Cisco exams, because it makes a lot of mistakes
2
C. Client provisioning (Partially correct, but not the best)
Client provisioning is a sub-process of BYOD onboarding that can push certificates and configure supplicants.
However, in Cisco Identity Services Engine (ISE), client provisioning is more commonly tied to AnyConnect VPN clients and posture assessments, not full BYOD onboarding.
It does not necessarily handle all parts of certificate enrollment like SCEP does within the BYOD process.
C 1
Selected Answer: C
It is not byod, since it's not explicitly stating that it's about employees' own devices, but it's rather just client provisioning
D 1
Selected Answer: D
D for sure. I've done this.
A 1
Selected Answer: A
I think it's A - BYOD
A 1
Selected Answer: A
Jessie and sully seem to have done good research on the topic
1
Answer is a
C 1
Selected Answer: C
Client Provisioning is the process of letting devices connect to the network. BYOD is more about allowing personal devices to connect. Client provisioning is the most suitable response, given the options available.
A 1
Selected Answer: A
I'll go with A here.
Option A is the full process of securely bringing a personal (non-corporate) device onto the network and includes:
• Authenticating the user
• Installing a certificate
• Configuring the supplicant (like 802.1X or EAP-TLS)
• Applying network access policies
• It uses client provisioning as a step in the process.
A 1
Selected Answer: A
ISE Cert Guide, p. 487. "BYOD onboarding: it includes registering a device with ISE, provisioning the certificate to the device, and configuring the device's supplicant."
A 1
Selected Answer: A
If a device supports native supplicant installation, the BYOD portal can be used; otherwise, the Client provisioning portal is used.
C 1
Selected Answer: C
C is the way to go
C 1
Selected Answer: C
Explicación técnica (nivel Cisco ISE / Enterprise)
En entornos de Cisco Identity Services Engine, el proceso de client provisioning es el mecanismo que se usa para:
Instalar de forma automática el supplicant 802.1X
Desplegar certificados digitales en el endpoint
Configurar perfiles de red (EAP-TLS, PEAP, etc.)
Preparar el dispositivo para autenticación segura
👉 Esto es justo lo que describe la pregunta:
configurar supplicant + desplegar certificados en dispositivos (sobre todo móviles)
A 1
Selected Answer: A
In BYOD, the certificate is deployed automatically for secure cert based authentication.