Q27Endpoint Protection and DetectionMultiple answers
Which two parameters are used in device compliance checks? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 19
B, E 12
Selected Answer: BE
The answer is BE. Based on work experience. Also see the link below. Checking the EPP version is not an option or parameter for device compliance checks. Registry files and operating system version are parameters you can select for your compliance checks.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#id_16997
5
AB is correct!
Table 5. OPSWAT API Versions
Posture Condition
Compliance Module Version
OPSWAT
Antivirus
3.x or earlier
Antispyware
3.x or earlier
Antimalware
4.x or later
Disk Encryption
3.x or earlier and 4.x or later
Patch Management
3.x or earlier and 4.x or later
USB
4.x or later
Non-OPSWAT
File
Any version
Application
Any version
Compound
Any version
Registry
Any version
Service
Any version
3
may be - A and B - >
may be this Compliance Module -https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html#ID1263
From the Compliance Module drop-down list, choose the required compliance module:
4.x or Later: Supports antimalware, disk encryption, patch management, and USB conditions.
3.x or Earlier: Supports antivirus, antispyware, disk encryption, and patch management conditions.
Any Version: Supports file, service, registry, application, and compound conditions.
For more information about compliance module, see Compliance Module.
3
if you choose C go back to your study book
3
I agree with your answer. It should be B and E.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/reorg/b_compliance_2_4.html
C, E 2
Selected Answer: CE
Must be C and E
A, E 2
Selected Answer: AE
Windows registry values, DHCP snooping checks, and DNS integrity checks are not normally used as parameters for device compliance checks, although they may be part of a more comprehensive security strategy.
B, E 2
Selected Answer: BE
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html#id_38954
Search Operating System and Registry and you'll find both
A, B 2
Selected Answer: AB
OS version cannot be used as a posture condition. If you have to allow Windows 11 only, you need an authorization rule and not a rule in a posture policy.
However, EPP version can be verified if it is a supported antimalware software. For example, you can allow FireEye 34.x and 35.x as a posture requirement but not allow older versions.
C, E 1
Selected Answer: CE
I prefer CE
A, B 1
Selected Answer: AB
A and B
Can't be E because it is not a selectable option under the conditions in ISE.
B, E 1
Selected Answer: BE
I'd go with B and E too, only because it's a Cisco exam and the others have solid evidence this is the answer Cisco wants. The EPP version is likely not as important as being up to date with definitions. I do like A though (if this were a "choose three answers"), since old EPP versions would have vulnerabilities.
1
Technically you can. https://community.cisco.com/t5/image/serverpage/image-id/36553iEFB399C948A7A0F3/image-dimensions/2000?v=v2&px=-1
1
Agreed, answers should be A & E.
1
EPP is antimalware, antispyware, and antivirus, which is listed along with registry.
OS version is not a compliance check; selecting the OS version identifies which compliance checks apply.
Answer is A, B.
B, E 1
Selected Answer: BE
A cannot be right because you can check the signature updates of the EDR, but not the version itself, which does not help at all.
A, B 1
Selected Answer: AB
Operating system is used as a filter for which posture requirements are set for the endpoint, but it is not a parameter itself. You can set a minimum Secure Client version or the value/existence of a registry key as a requirement to join.
A, B 1
Selected Answer: AB
I do not see OS version checking as an option.
File Condition Settings
Firewall Condition Settings
Registry Condition Settings
Continuous Endpoint Attribute Monitoring
Application Condition Settings
Service Condition Settings
Posture Compound Condition Settings
AntiVirus Condition Settings
Antispyware Compound Condition Settings
Antimalware Condition Settings
Dictionary Simple Condition Settings
Dictionary Compound Condition Settings
Patch Management Condition Settings
Disk Encryption Condition settings
USB Condition Settings
Hardware Attributes Condition Settings
Posture External DataSource Condition
A, E 1
Selected Answer: AE
A&E Correct, this posturing