Implementing and Configuring Cisco Identity Services Engine (SISE) — Question 289
An administrator must provide network access to legacy Windows endpoints with a specific device type and operating system version using Cisco ISE profiler services. The ISE profiler services and access switches must be configured to identify endpoints using the dhcp-class-identifier and parameters-request-list attributes from the DHCP traffic. These configurations were performed:
• enabled the DHCP probe in Cisco ISE
• configured the Cisco ISE PSN interface to receive DHCP packets
• configured the attributes in custom profiling conditions
• configured a custom profiling policy
• configured an authorization rule with permit access
Which action completes the configuration?
Answer options
- A. Configure the Cisco ISE PSN interface to receive SPAN DHCP traffic.
- B. Configure the switches to send copies of the DHCP traffic to the Cisco ISE PSN.
- C. Enable the DHCP SPAN probe in Cisco ISE primary server.
- D. Configure the switches to relay DHCP packets to the Cisco ISE PSN.
Correct answer: D
Explanation
The correct answer is D because configuring the switches to relay DHCP packets to the Cisco ISE PSN is necessary for ISE to receive the DHCP traffic, which is critical for profiling. Option A is incorrect because SPAN traffic is not the same as relaying DHCP packets. Option B is a partial solution but does not specify the necessary action of forwarding the packets. Option C refers to enabling a DHCP SPAN probe, which is not relevant to the existing configuration needs.