An organization has a fully distributed Cisco ISE deployment.
When implementing probes, an administrator must scan for unknown endpoints to learn the IP-to
MAC address bindings. The scan is complete on one PSN, but the information is not available on the others.
What must be done to make the information available?
- Cisco ISE must be configured to learn the IP-MAC binding of unknown endpoints via RADIUS authentication, not via scanning.
- Cisco ISE must learn the IP-MAC binding of unknown endpoints via DHCP profiling, not via scanning.
- Scanning must be initiated from the MnT node to centrally gather the information.
- Scanning must be initiated from the PSN that last authenticated the endpoint.
Answer(s): D
Reference:
https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456
Reveal Solution Next Question