Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam 300-715 topic 1 question 182 discussion

Actual exam question from APICS's CSCP
Question #: 182
Topic #: 1
[All CSCP Questions]

A user is attempting to register a BYOD device to the Cisco ISE deployment, but needs to use the onboarding policy to request a digital certificate and provision the endpoint. What must be configured to accomplish this task?

  • A. The BYOD flow to ensure that the endpoint will be provisioned prior to registering.
  • B. The posture provisioning policy to give the endpoint all necessary components prior to registering.
  • C. A native supplicant provisioning policy to redirect them to the BYOD portal for onboarding.
  • D. The Cisco AnyConnect provisioning policy to provision the endpoint for onboarding.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
YmerG
Highly Voted 1 year, 8 months ago
Selected Answer: C
A native supplicant provisioning policy is used to redirect the BYOD user to the Cisco ISE BYOD portal for onboarding. The BYOD portal can be used to request a digital certificate and provision the endpoint, as well as to download and install the necessary certificates and software components. Option A is incorrect because the BYOD flow is not used to provision the endpoint, but rather to authorize access to the network. Option B is incorrect because the posture provisioning policy is not used to provision the endpoint during the onboarding process. Option D is incorrect because the Cisco AnyConnect provisioning policy is not used for onboarding BYOD devices, but rather for onboarding corporate-owned devices.
upvoted 6 times
...
NikoTomas
Most Recent 8 months, 3 weeks ago
Correct is C) - Device registration will take place first (MAC address – Endpoint Identity Group: RegisteredDevices, flag BYODregistration), and then Device Enrollment – setting up the supplicant and issuing the X.509 certificate. A) is therefore incorrect (the truth is exactly the opposite): "BYOD flow to ensure that the endpoint will be provisioned prior to registering" - BYOD primarily provisions the native supplicant. D) is therefore incorrect (states provisioning Cisco AC) Network Setup Assistant (NSA) --> Native Supplicant Provisioning (NSP) - Web Redirection in the Authorization profile is of the type "Native Supplicant Provisioning" --> Value "BYOD Portal" (see figure 16-54 in ebook) - That's why BYOD Portal is like subset of NSP (from Authorization Profile point of view) C) correctly says that the NSP policy redirects the user to the BYOD portal for onboarding (see Authorization Profile). D) "Posture provisioning" – does not apply to BYOD device provisioning.
upvoted 2 times
...
XBfoundX
11 months, 3 weeks ago
I have to say that I'm wrong actually..... DO NOT GET CONFUSED LIKE ME ABOUT THIS... Answer is C because reading that better is not posture provisioning policy... That policy is needed for the actual posture of the client and you will specify the remediation steps for resolve in case that the client is not compliant The client provisioning policy or as they say native supplicant provisioning policy is needed for deploying the configuration of the cisco anyconnect agent or any agent that you want to deploy this policy is just needed based on who you are and other conditions for deploying the right agent. I'm sorry for put confusion in the community. Hope that I solved that. YmerG was right
upvoted 3 times
...
XBfoundX
1 year ago
The answer here is B just lab it if u can. Basically when you do onboarding of BYOD what you do is configuring a client provisioning policy for the BYOD so that the client will download the setup.exe with the certificate that the client will use for the onboarding. So the client is gonna be redirected to the BYOD portal and then the client will download this .exe, it will begin the setup and after that the certificate as said before is installed. After that the client will use the certificate to be authenticated, in ISE there will be a policy that is gonna match if the user is BYOD Portal registered equal Yes, if EAP-TLS and if the radius calling-station id is matching the CN (It will be the mac address of the device) then the client will be authenticated correctly.
upvoted 1 times
...
denverfly
1 year, 6 months ago
Selected Answer: B
The correct answer is The posture provisioning policy to give the endpoint all necessary components prior to registering. The posture provisioning policy is used to configure the endpoint before it is registered with Cisco ISE. This policy can be used to install software, configure settings, and request digital certificates
upvoted 1 times
...
DeviantSpy
1 year, 6 months ago
Selected Answer: C
C is correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...