🔥 3-day streak
Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715)24 / 139
Question 24 of 139

A network administrator configures an ISE authentication policy for a dot1x-based wired deployment. Contractors authenticate using EAP-TLS certificates stored in an LDAP directory, while full-time employees authenticate using PEAP-MSCHAPv2 credentials in Active Directory. Both user types hit the same authentication policy rule. The administrator wants ISE to first attempt to validate the user against Active Directory, and if the user is not found there, fall through and check the LDAP store before rejecting the request. Which configuration achieves this behavior?

Reviewed for accuracy · Report an issueNext question