- Home
- Networking
- CCNP Security 300-208
61.
ISE Guest Services use which of the following approaches to authenticate a user?
- A.Badge
- B.WebAuth
- C.TACACS+
- D.SSH
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
When a guest connects to the network, they are given a web-redirect authorization policy. This web redirect will intercept any attempts to browse the Internet, forcing the guest user to a webpage where they will authenticate—that is, WebAuth. |
62.
The sponsor and guest portals can run on which of the following ISE personas?
- A.Admin
- B.MnT
- C.PSN
- D.a and b
- E.a and c
- F.b and c
- Answer & Explanation
- Report
Answer : [C]
Explanation :
Explanation :
The sponsor and guest portals can run on any PSN that has session services running. |
63.
True or False: A network administrator can customize the guest portals to run on any port
greater than 1024.
- A.True
- B.False
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
Currently, the ISE guest portals can run only on those ports between 8000 and 8999. |
64.
Which default sponsor groups are available on ISE? (Select three.)
- A.SponsorAllAccounts
- B.SponsorADAccounts
- C.SponsorAdministrator
- D.SponsorGroupGrpAccounts
- E.SponsorAllUsers
- F.SponsorGroupOwnAccounts
- Answer & Explanation
- Report
Answer : [A, D, F]
Explanation :
Explanation :
The three default sponsor groups on ISE are SponsorAllAccounts, SponsorGroupGrpAccounts, and SponsorGroupOwnAccounts. |
65.
When using Active Directory group membership as authentication and authorization for
sponsors, which of the following must occur?
- A.ISE must be associated to the domain.
- B.The sponsor must create all guest accounts on the Active Directory Server.
- C.The Active Directory identity store must be part of the identity source sequence for the sponsor portal.
- D.a and b.
- E.b and c.
- F.a and c.
- Answer & Explanation
- Report
Answer : [F]
Explanation :
Explanation :
To use Active Directory group membership as the source of authentication and authorization for sponsors, ISE must first be associated to the domain. Furthermore, the AD identity store must also be a part of the identity source sequence that is in use for the sponsor portal. If you choose, you can provide a differentiated level of guest account creation based on the AD group membership |