Question 1 of 30
In a large enterprise network utilizing Cisco\'s Software-Defined Access (SDA) architecture, a network engineer is tasked with implementing a new policy that requires all devices connecting to the network to authenticate using 802.1X. The engineer must also ensure that devices are segmented based on their roles (e.g., employee devices, guest devices, and IoT devices) to enhance security. Given this scenario, which approach should the engineer take to effectively implement this policy while maintaining network performance and security?
Implement Cisco Identity Services Engine (ISE) to manage device authentication and authorization, leveraging profiling to classify devices and applying appropriate access control policies based on their roles.
Use a traditional VLAN segmentation approach without integrating ISE, relying solely on static IP assignments to differentiate device types.
Configure access control lists (ACLs) on the switches to restrict traffic based on device types, without implementing any form of dynamic authentication.
Deploy a firewall at the network perimeter to handle all authentication requests and enforce segmentation based on IP addresses.

Preparing for CISCO 500-470 Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free