Câu 151: 400-251: CCIE Security Written Exam
A sneaky employee using an Android phone on your network has disabled DHCP, enabled its firewall, modified its HTTP user-agent header, to fool ISE into profiling it as a Windows 10 machine connected to the wireless network. This user can now get authorization for unrestricted network access using his ActiveDirectory c…
Nội dung câu hỏi
A sneaky employee using an Android phone on your network has disabled DHCP, enabled its firewall, modified its HTTP user-agent header, to fool ISE into profiling it as a Windows 10 machine connected to the wireless network. This user can now get authorization for unrestricted network access using his ActiveDirectory credentials, because your policy states that a Windows device using AD credentials should be able to get full network access. However, an Android device should only get access to the web proxy. Which two steps can you take to avoid this sort of rogue behavior? (Choose two.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Allow only certificate-based authentication from Windows endpoints, such as EAP-TLS or PEAP-TLS. If the endpoint uses MSCHAPv2 (EAP or PEAP), the user is given only restricted access. — đáp án hiện tại
- B. Create an authentication rule that allows only a session with a specific HTTP user-agent header.
- C. Modify the authorization policy to allow only Windows machines that have passed Machine Authentication to get full network access. — đáp án hiện tại
- D. Perform CoA to push a restricted access when the machine is acquiring address using DHCP.
- E. Add an authorization policy before the Windows authorization policy that redirects a user with a static IP to a web portal for authentication.
- F. Chain an authorization policy to the Windows authorization policy that performs additional NMAP scans to verify the machine type, before access is allowed.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.