ETExamTower
Q27Endpoint Protection and DetectionMultiple answers

Which two parameters are used in device compliance checks? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
35% (9)
E
31% (8)
A
27% (7)
C
8% (2)
D
0% (0)
Discussion · 19
B, E 12
Selected Answer: BE The answer is BE. Based on work experience. Also see the link below. Checking the EPP version is not an option or parameter for device compliance checks. Registry files and operating system version are parameters you can select for your compliance checks. https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#id_16997
5
AB is correct! Table 5. OPSWAT API Versions Posture Condition Compliance Module Version OPSWAT Antivirus 3.x or earlier Antispyware 3.x or earlier Antimalware 4.x or later Disk Encryption 3.x or earlier and 4.x or later Patch Management 3.x or earlier and 4.x or later USB 4.x or later Non-OPSWAT File Any version Application Any version Compound Any version Registry Any version Service Any version
3
may be - A and B - > may be this Compliance Module -https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html#ID1263 From the Compliance Module drop-down list, choose the required compliance module: 4.x or Later: Supports antimalware, disk encryption, patch management, and USB conditions. 3.x or Earlier: Supports antivirus, antispyware, disk encryption, and patch management conditions. Any Version: Supports file, service, registry, application, and compound conditions. For more information about compliance module, see Compliance Module.
3
if you choose C go back to your study book
3
I agree with your answer. It should be B and E. https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/reorg/b_compliance_2_4.html
C, E 2
Selected Answer: CE Must be C and E
A, E 2
Selected Answer: AE Windows registry values, DHCP snooping checks, and DNS integrity checks are not normally used as parameters for device compliance checks, although they may be part of a more comprehensive security strategy.
B, E 2
Selected Answer: BE https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html#id_38954 Search Operating System and Registry and you'll find both
A, B 2
Selected Answer: AB OS version cannot be used as a posture condition. If you have to allow Windows 11 only, you need an authorization rule and not a rule in a posture policy. However, EPP version can be verified if it is a supported antimalware software. For example, you can allow FireEye 34.x and 35.x as a posture requirement but not allow older versions.
C, E 1
Selected Answer: CE I prefer CE
A, B 1
Selected Answer: AB A and B Can't be E because it is not a selectable option under the conditions in ISE.
B, E 1
Selected Answer: BE I'd go with B and E too, only because it's a Cisco exam and the others have solid evidence this is the answer Cisco wants. The EPP version is likely not as important as being up to date with definitions. I do like A though (if this were a "choose three answers"), since old EPP versions would have vulnerabilities.
1
Technically you can. https://community.cisco.com/t5/image/serverpage/image-id/36553iEFB399C948A7A0F3/image-dimensions/2000?v=v2&px=-1
1
Agreed, answers should be A & E.
1
EPP is antimalware, antispyware, and antivirus, which is listed along with registry. OS version is not a compliance check; selecting the OS version identifies which compliance checks apply. Answer is A, B.
B, E 1
Selected Answer: BE A cannot be right because you can check the signature updates of the EDR, but not the version itself, which does not help at all.
A, B 1
Selected Answer: AB Operating system is used as a filter for which posture requirements are set for the endpoint, but it is not a parameter itself. You can set a minimum Secure Client version or the value/existence of a registry key as a requirement to join.
A, B 1
Selected Answer: AB I do not see OS version checking as an option. File Condition Settings Firewall Condition Settings Registry Condition Settings Continuous Endpoint Attribute Monitoring Application Condition Settings Service Condition Settings Posture Compound Condition Settings AntiVirus Condition Settings Antispyware Compound Condition Settings Antimalware Condition Settings Dictionary Simple Condition Settings Dictionary Compound Condition Settings Patch Management Condition Settings Disk Encryption Condition settings USB Condition Settings Hardware Attributes Condition Settings Posture External DataSource Condition
A, E 1
Selected Answer: AE A&E Correct, this posturing