exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 774 discussion

Actual exam question from Cisco's 350-401
Question #: 774
Topic #: 1
[All 350-401 Questions]

Which solution simplifies management of secure access to network resources?

  • A. RFC 3580-based solution to enable authenticated access leveraging RADIUS and AV pairs
  • B. 802.1AE to secure communication in the network domain
  • C. ISE to automate network access control leveraging RADIUS AV pairs
  • D. TrustSec to logically group internal user environments and assign policies
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hamish88
Highly Voted 1 year, 8 months ago
Selected Answer: D
The answer is D. From 31 days before CCNP, page 524: Cisco TrustSec simplifies the provisioning and management of secure access to network services and applications.
upvoted 9 times
...
kozwe
Most Recent 1 month, 2 weeks ago
Selected Answer: C
Answer C. So, which one simplifies access management? Cisco ISE simplifies access management by automating authentication, authorization, and accounting (AAA) tasks. It centralizes the management of network access control policies, making it easier to enforce consistent security policies across a large network. TrustSec simplifies network segmentation and policy enforcement based on the identity of the user or device, but it requires ISE to function.
upvoted 1 times
...
matass_md
2 months ago
Selected Answer: C
C is correct. why it's not D : TrustSec enables role-based access control via SGTs (Security Group Tags) but requires ISE for identity management and policy enforcement.
upvoted 1 times
...
EvillNL
3 months, 1 week ago
Selected Answer: C
- Answer from ChatGPT: The correct answer is: C. ISE to automate network access control leveraging RADIUS AV pairs
upvoted 1 times
...
post20
4 months, 3 weeks ago
Selected Answer: C
Answer C: While both technologies play crucial roles, ISE is the policy server that provides the foundation for managing access control and device authentication, while TrustSec is the enforcement layer that applies segmentation and policies to control traffic flows within the network. They work together to provide comprehensive security and simplified network access management. In the context of the question you’re dealing with, the right answer depends on whether the focus is on managing access policies (ISE) or on segmentation and policy enforcement (TrustSec).
upvoted 1 times
jmarko80
3 months, 2 weeks ago
ISE without Trust Sec does not guarantee profiled secure access to network resources. So the corret answer is D. TrustSec is a next-generation access control enforcement solution developed by Cisco to address the growing operational challenges related to maintaining firewall rules and ACLs by using Security Group Tag (SGT) tags. Trust sec is simpler then using "old" solution es.Firewall/Controller devices to enforce policies based on returned AV pair Radius (post authentication)
upvoted 2 times
...
...
NetworkJanitor
5 months, 1 week ago
Selected Answer: D
It's D TrustSec vs Cisco ISE Cisco TrustSec and Cisco Identity Services Engine (ISE) are complementary technologies that work together to provide network segmentation and access control: Cisco TrustSec - Software-defined segmentation solution that uses security group tags (SGTs) to enforce access policies - Simplifies network segmentation compared to traditional VLAN-based approaches - Allows segmentation of devices without redesigning the network1 Cisco ISE - Policy server designed to manage TrustSec - Defines and manages SGTs on the network - Handles authentication, authorization, and accounting (AAA) for network access hth
upvoted 2 times
kozwe
1 month, 2 weeks ago
How They Work Together: Cisco ISE authenticates users and devices, then assigns Security Group Tags (SGTs) to the authenticated entities. Cisco TrustSec then uses those SGTs to enforce policies (like what network segments the user or device can access) across the network. So, which one simplifies access management? Cisco ISE simplifies access management by automating authentication, authorization, and accounting (AAA) tasks. It centralizes the management of network access control policies, making it easier to enforce consistent security policies across a large network. TrustSec simplifies network segmentation and policy enforcement based on the identity of the user or device, but it requires ISE to function.
upvoted 1 times
...
NetworkJanitor
5 months, 1 week ago
So, yes C/ISE is the umbrella but D answer the question directly.
upvoted 2 times
...
...
ExamTaker1017
5 months, 1 week ago
Selected Answer: C
The answer is C.
upvoted 1 times
...
zbeugene7
6 months ago
It's C, because management of network access is much more than just TrueSec segmentation , ISE simplifies management through network visibility , centralized network/device access control, other functions
upvoted 2 times
...
IgorLVG
6 months, 2 weeks ago
Selected Answer: C
ISE is the answer because it have the data for reosurces access and the network
upvoted 2 times
...
Rfvaz
8 months, 1 week ago
Selected Answer: D
Answer D.
upvoted 1 times
...
a197cbf
9 months, 3 weeks ago
My vote is for D - TrustSec. Yes, ISE can automate, but TrustSec uses Contextual Identification to simplify the securing of network resources by using SGTs. For example, you can tag a server with the "HR" SGT. With that, TrustSec will only allow users/endpoints with the same HR SGT to access that server, and blocking any other endpoints from accessing it. Option C starts getting a bit too complicated by mentioning RADIUS AV pairs, but the TrustSec option seemed pretty clear-cut.
upvoted 2 times
...
merlow6674
10 months, 1 week ago
Answer is (C) Cisco Identity Services Engine (ISE) automates network access control by leveraging RADIUS Attribute-Value (AV) pairs.
upvoted 1 times
...
[Removed]
10 months, 2 weeks ago
Selected Answer: C
I go with C. https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215525-use-radius-for-device-administration-wit.html
upvoted 1 times
...
[Removed]
11 months, 1 week ago
I go with C.
upvoted 3 times
...
Shri_Fcb10
11 months, 1 week ago
Selected Answer: C
the solution that specifically emphasizes the automation and central management of network access control, leveraging RADIUS attributes (AV pairs), is Cisco Identity Services Engine (ISE). ISE not only simplifies secure access management but also integrates well with existing network infrastructure to provide comprehensive access control and policy enforcement. Therefore, while TrustSec (D) is an important solution for managing secure access through logical grouping and policy assignment, the best answer in terms of simplifying management specifically through automation and leveraging RADIUS AV pairs is C
upvoted 3 times
...
IgorLVG
1 year, 1 month ago
ISE is the correct answer. The secure access in cisco is ISE.
upvoted 2 times
...
IgorLVG
1 year, 1 month ago
ISE is the Answer. The description of the device is a NAC -> ISE
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago