- Home
- Networking
- CCNP Security 300-208
46.
What is an authorization profile?
- A.An authorization profile is a rule in the policy table that is formatted like “IF condition THEN result.”
- B.An authorization profile is created to determine which identity store to validate the credentials with.
- C.An authorization profile is a sequential list of identity stores to validate the credentials with.
- D.An authorization profile is the mandatory result of an authorization rule.
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
An authorization profile is the required authorization result that is made up of multiple RADIUS attributes. These RADIUS results will affect the ultimate security policy deployed to the NAD on behalf of the endpoint. |
47.
What is the purpose of an authorization profile?
- A.It contains the TACACS+ response (Access-Accept or Access-Reject) along with the additional authorization attributes to be sent to the network device for enforcement.
- B.It contains the RADIUS response (Access-Accept or Access-Reject) along with the additional authorization attributes to be sent to the network device for enforcement.
- C.It contains the RADIUS response (Continue or Terminate) along with additional authorization attributes to be sent to the network device for enforcement.
- D.It contains the TACACS+ response (Continue or Terminate) along with additional authorization attributes to be sent to the network device for enforcement.
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
It contains the RADIUS response (Access-Accept or Access-Reject) along with the additional authorization attributes to be sent to the network device for enforcement. |
48.
Which of the following options are part of the common tasks section of an authorization
profile?
- A.Access-Type (Continue or Terminate), DACL-Name, Web-Redirection, Auto Smart Port
- B.Access-Type (Accept or Reject), DACL-Name, Web-Redirection, Auto Smart Port
- C.DACL-Name, Role-Assignment, Local WebAuth, Auto Smart Port
- D.DACL-Name, Web-Redirection, Local WebAuth, Auto Smart Port
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
DACL-Name, Web-Redirection, Local WebAuth, Auto Smart Port. These common tasks, as well as the others, are the most often used RADIUS AVPs that will be sent to the NAD for secure policy enforcement of the endpoint. |
49.
Which of the following is correct?
- A.An authorization policy contains authorization rules. Each rule will have at least one authorization profile.
- B.An authorization rule contains authorization policies. Each policy will have at least one authorization profile.
- C.An authentication policy contains authorization rules. Each rule must have an authentication result.
- D.An authentication rule contains the authorization profiles. Each profile must contain one authentication result.
- Answer & Explanation
- Report
Answer : [A]
Explanation :
Explanation :
An authorization policy contains authorization rules. Each rule will have at least one authorization profile. |
50.
True or False? Condition attributes can be saved into a library for future use and improved
readability.
- A.True
- B.False
- Answer & Explanation
- Report
Answer : [A]
Explanation :
Explanation :
True. Condition attributes can be saved into a library for future use and improved readability. |