- 积分
- 88
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 注册时间
- 2014-1-25
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
|
楼主 |
发表于 2020-11-5 23:19:41
|
显示全部楼层
QUESTION 1131 \7 q B& z: K& l8 D+ [
Under which two circumstances is a CoA issued? (Choose two)8 }; A- g8 F3 t! X
A. A new authentication rule was added to the policy on the Policy Service node.% R- U% H8 e+ d! Z' n' _: Q
B. An endpoint is profiled for the first time.
# v& U, ^. w' f" ] p/ {C. A new Identity Service Engine server is added to the deployment with the Administration persona6 `3 D- n* {# M& P9 f! Q/ d+ y
D. A new Identity Source Sequence is created and referenced in the authentication policy.$ Y$ V! P- E; b: `* I. Z
E. An endpoint is deleted on the Identity Service Engine server.
+ G8 _! j: o3 d4 U, W FCorrect Answer: BE1 U9 ^/ v4 `# M" |, M
4 u7 j) _ a/ a n3 B
+ h( l* x& H* U, T7 Q9 IExplanation7 l* t1 A0 w- X" E. m( L& O# _- N
4 g1 t/ g: g+ Q& w3 ]
The profiling service issues the change of authorization in the following cases:/ _% _$ S! i3 p* R9 S* {
– Endpoint deleted—When an endpoint is deleted from the Endpoints page and the endpoint is disconnected or removed from the network.+ e& D* Z7 N# t; o F% M. ]
An exception action is configured—If you have an exception action configured per profile that leads to an unusual or an unacceptable event from that endpoint. The profiling service moves the endpoint to the corresponding static profile by issuing a CoA.( {6 z. t5 i6 B9 Y
– An endpoint is profiled for the first time—When an endpoint is not statically assigned and profiled for the first time; for example, the profile changes from an unknown to a known profile.5 @9 z6 K% F7 e# e6 V- l
+ An endpoint identity group has changed—When an endpoint is added or removed from an endpoint identity group that is used by an authorization policy.
) | Y; ^" u1 v- e zThe profiling service issues a CoA when there is any change in an endpoint identity group, and the endpoint identity group is used in the authorization policy for the following:: q5 h* ^7 b3 M, w! r1 p
++ The endpoint identity group changes for endpoints when they are dynamically profiled
6 |& \; q& ?6 d/ }" I L5 r6 [++ The endpoint identity group changes when the static assignment flag is set to true for a dynamic endpoint
# W5 d: f$ `/ E7 r– An endpoint profiling policy has changed and the policy is used in an authorization policy—When an endpoint profiling policy changes, and the policy is included in a logical profile that is used in an authorization policy. The endpoint profiling policy may change due to the profiling policy match or when an endpoint is statically assigned to an endpoint profiling policy, which is associated to a logical profile. In both the cases, the profiling service issues a CoA, only when the endpoint profiling policy is used in an authorization policy.
( Q e* e6 A3 ?
2 ^- ~! A/ i* h9 P% OReference: https://www.cisco.com/c/en/us/td ... chapter_010100.html |
6#
2020-11-5 23:19:41
回复(0)
收起回复
|