Implementing and Configuring Cisco Identity Services Engine (SISE) — Question 276
An engineer configures Cisco ISE and Cisco Catalyst switches to enforce Cisco TrustSec policies. The engineer must use a nondisruptive deployment approach for new devices by deploying TrustSec policies in staging, preproduction, and production. Which action must be taken to complete the configuration?
Answer options
- A. Configure Security Group Tag Exchange Protocol on the new devices and integrate the devices in groups with Cisco ISE.
- B. Configure policy matrices in Cisco ISE and assign the new devices to the policy matrices.
- C. Integrate the new devices in staging, preproduction, and production network device groups.
- D. Configure a different security group tag for the new devices in the staging, preproduction, and production stages.
Correct answer: C
Explanation
The correct answer is C because integrating the new devices into the appropriate network device groups ensures that they receive the correct TrustSec policies in each stage of deployment. Options A and B do not directly address the need for staging, preproduction, and production group integrations, while option D suggests a different security group tag, which is not necessary for a nondisruptive deployment.