CCNP Security Identity Management SISE 300-715 Official Cert Guide, 1st edition

Published by Cisco Press (October 30, 2020) © 2021

  • Aaron Woland
  • Katherine McNamara
Products list
  • Available for purchase from all major ebook resellers, including InformIT.com
Introduction xxxvi

Part I Authentication, Authorization, and Accounting

Chapter 1 Fundamentals of AAA 2

“Do I Know This Already?” Quiz 3

Foundation Topics 5

Comparing and Selecting AAA Options 5

TACACS+ 7

RADIUS 12

Comparing RADIUS and TACACS+ 16

Exam Preparation Tasks 16

Review All Key Topics 16

Define Key Terms 17

Q&A 17

Chapter 2 Identity Management 18

“Do I Know This Already?” Quiz 18

Foundation Topics 20

What Is an Identity? 20

Identity Stores 20

Identity Source Sequences 34

Special Identity Sources 35

Exam Preparation Tasks 36

Review All Key Topics 36

Define Key Terms 36

Q&A 36

Chapter 3 Extensible Authentication Protocol (EAP) over LAN: 802.1X 38

“Do I Know This Already?” Quiz 38

Foundation Topics 41

Extensible Authentication Protocol 41

EAP over LAN (802.1X) 41

Supplicant Options 50

Exam Preparation Topics 73

Review All Key Topics 73

Define Key Terms 74

Q&A 74

Chapter 4 Non-802.1X Authentication 76

“Do I Know This Already?” Quiz 76

Foundation Topics 79

Devices Without a Supplicant 79

MAC Authentication Bypass 80

Web Authentication 83

Remote-Access Connections 88

EasyConnect 89

Exam Preparation Tasks 90

Review All Key Topics 90

Define Key Terms 91

Q&A 91

Chapter 5 Introduction to Advanced Concepts 92

“Do I Know This Already?” Quiz 92

Foundation Topics 95

Change of Authorization 95

Automating MAC Authentication Bypass (MAB) 96

Posture Assessment 99

Mobile Device Management (MDM) 101

Exam Preparation Tasks 102

Review All Key Topics 102

Define Key Terms 102

Q&A 103

Part II Cisco Identity Services Engine

Chapter 6 Cisco Identity Services Engine Architecture 104

“Do I Know This Already?” Quiz 104

Foundation Topics 106

What Is Cisco ISE? 106

Personas 108

Physical or Virtual Appliances 111

ISE Deployment Scenarios 113

Exam Preparation Tasks 120

Review All Key Topics 120

Define Key Terms 120

Q&A 120

Chapter 7 A Guided Tour of the Cisco ISE Graphical User Interface (GUI) 122

“Do I Know This Already?” Quiz 123

Foundation Topics 125

Logging in to ISE 125

Organization of the ISE GUI 142

Types of Policies in ISE 171

Exam Preparation Tasks 173

Review All Key Topics 173

Define Key Term 173

Q&A 173

Chapter 8 Initial Configuration of Cisco ISE 174

“Do I Know This Already?” Quiz 174

Foundation Topics 177

Cisco Identity Services Engine Form Factors 177

Bootstrapping Cisco ISE 177

Network Devices 192

ISE Identity Stores 194

Exam Preparation Topics 204

Review All Key Topics 204

Define Key Terms 204

Q&A 205

Chapter 9 Authentication Policies 206

“Do I Know This Already?” Quiz 207

Foundation Topics 209

The Relationship Between Authentication and Authorization 209

Authentication Policy 210

Understanding Policy Sets 211

Understanding Authentication Policies 216

Common Authentication Policy Examples 220

More on MAB 227

Restore the Authentication Policy 229

Exam Preparation Tasks 230

Review All Key Topics 230

Q&A 230

Chapter 10 Authorization Policies 232

“Do I Know This Already?” Quiz 232

Foundation Topics 235

Authentication Versus Authorization 235

Authorization Policies 235

Saving Conditions for Reuse 249

Exam Preparation Tasks 256

Review All Key Topics 256

Define Key Terms 256

Q&A 256

Part III Implementing Secure Network Access

Chapter 11 Implement Wired and Wireless Authentication 258

“Do I Know This Already?” Quiz 259

Foundation Topics 261

Authentication Configuration on Wired Switches 261

Authentication Configuration on WLCs 276

Verifying Dot1x and MAB 295

Live Sessions 303

Looking Forward 303

Exam Preparation Tasks 303

Review All Key Topics 303

Define Key Terms 304

Q&A 304

Chapter 12 Web Authentication 306

“Do I Know This Already?” Quiz 306

Foundation Topics 309

Web Authentication Scenarios 309

Configuring Centralized Web Authentication 313

Building CWA Authorization Policies 322

Verifying Centralized Web Authentication 324

Exam Preparation Tasks 331

Review All Key Topics 331

Define Key Terms 331

Q&A 332

Chapter 13 Guest Services 334

“Do I Know This Already?” Quiz 334

Foundation Topics 337

Guest Services Overview 337

Portals, Portals, and More Portals! 341

Configuring Guest Portals and Authorization Rules 351

Sponsors 381

SAML Authentication 394

Exam Preparation Tasks 400

Review All Key Topics 400

Define Key Terms 401

Q&A 401

Chapter 14 Profiling 402

“Do I Know This Already?” Quiz 402

Foundation Topics 404

ISE Profiler 404

Infrastructure Configuration 424

Profiling Policies 429

ISE Profiler and CoA 442

Profiles in Authorization Policies 450

Verify Profiling 454

Exam Preparation Topics 458

Review All Key Topics 458

Define Key Terms 458

Q&A 458

Part IV Advanced Secure Network Access

Chapter15 Certificate-Based Authentication 460

“Do I Know This Already?” Quiz 460

Foundation Topics 463

Certificate Authentication Primer 463

A Common Misconception About Active Directory 469

EAP-TLS 470

Configuring ISE for Certificate-Based Authentications 470

Exam Preparation Tasks 479

Review All Key Topics 479

Define Key Terms 480

Q&A 480

Chapter 16 Bring Your Own Device 482

“Do I Know This Already?” Quiz 483

Foundation Topics 485

Configuring NADs for Onboarding 489

ISE Configuration for Onboarding 495

BYOD Onboarding Process Detailed 523

Verifying BYOD Flows 534

MDM Onboarding 535

Managing Endpoints 542

The Opposite of BYOD: Identify Corporate Systems 545

Exam Preparation Topics 546

Review All Key Topics 547

Define Key Terms 547

Q&A 547

Chapter 17 TrustSec and MACsec 548

“Do I Know This Already?” Quiz 548

Foundation Topics 551

Ingress Access Control Challenges 551

What Is TrustSec? 555

What Is a Security Group Tag? 556

What Is the TrustSec Architecture? 557

TrustSec-Enabled Network Access Devices 558

Network Device Admission Control (NDAC) 566

Defining the SGTs 572

Classification 575

Transport: SGT Exchange Protocol (SXP) 581

Transport: Native Tagging 593

Enforcement 597

Software-Defined Access (SD-Access) 613

MACsec 614

Exam Preparation Tasks 623

Review All Key Topics 623

Define Key Terms 623

Q&A 624

Chapter 18 Posture Assessment 626

“Do I Know This Already?” Quiz 626

Foundation Topics 629

Posture Assessment with ISE 629

Configuring Posture 636

The Endpoint Experience 695

Mobile Posture 707

Exam Preparation Tasks 713

Review All Key Topics 713

Define Key Terms 713

Q&A 713

Part V Safely Deploying in the Enterprise

Chapter 19 Deploying Safely 714

“Do I Know This Already?” Quiz 714

Foundation Topics 717

Why Use a Phased Approach? 717

Comparing authentication open to Standard 802.1X 719

Prepare ISE for a Staged Deployment 720

Monitor Mode 722

Low-Impact Mode 725

Closed Mode 728

Transitioning from Monitor Mode to Your End State 730

Wireless Networks 731

Exam Preparation Tasks 731

Review All Key Topics 731

Q&A 732

Chapter 20 ISE Scale and High Availability 734

“Do I Know This Already?” Quiz 734

Foundation Topics 737

Configuring ISE Nodes in a Distributed Environment 737

Understanding the High Availability Options Available 743

Using Load Balancers 751

Maintaining ISE Deployments 757

Exam Preparation Tasks 761

Review All Key Topics 761

Define Key Term 761

Q&A 762

Chapter 21 Troubleshooting Tools 764

“Do I Know This Already?” Quiz 764

Foundation Topics 766

Logging 766

Diagnostic Tools 785

Troubleshooting Methodology 804

Troubleshooting Outside of ISE 808

Exam Preparation Tasks 815

Review All Key Topics 815

Q&A 816

Part VI Extending Secure Access Control

Chapter 22 ISE Context Sharing and Remediation 818

“Do I Know This Already?” Quiz 818

Foundation Topics 820

Integration Types in the ISE Ecosystem 820

pxGrid 825

Exam Preparation Tasks 867

Review All Key Topics 867

Define Key Terms 867

Q&A 867

Chapter 23 Threat Centric NAC 868

“Do I Know This Already?” Quiz 868

Foundation Topics 871

Vulnerabilities and Threats, Oh My! 871

Integrating Vulnerability Assessment Sources 872

Integrating with Threat Sources 890

Exam Preparation Tasks 904

Review All Key Topics 904

Define Key Terms 905

Q&A 905

Part VII Device Administration AAA

Chapter 24 Device Administration AAA with ISE 906

“Do I Know This Already?” Quiz 906

Foundation Topics 909

Device Administration AAA Refresher 909

Device Administration in ISE 910

Device Administration Global Settings 917

Device Administration Work Center 919

Exam Preparation Tasks 928

Review All Key Topics 928

Q&A 928

Chapter 25 Configuring Device Administration AAA with Cisco IOS 930

“Do I Know This Already?” Quiz 930

Foundation Topics 932

Overview of IOS Device Administration AAA 932

Configure ISE and an IOS Device for Device Administration AAA 936

Testing and Troubleshooting 951

Exam Preparation Tasks 966

Review All Key Topics 966

Define Key Terms 967

Q&A 967

Chapter 26 Configuring Device Admin AAA with the Cisco WLC 968

“Do I Know This Already?” Quiz 968

Foundation Topics 971

Overview of WLC Device Administration AAA 971

Configure ISE and the WLC for Device Administration AAA 972

Testing and Troubleshooting 981

Exam Preparation Tasks 986

Review All Key Topics 986

Q&A 987

Part VIII Final Preparation

Chapter 27 Final Preparation 988

Hands-on Activities 988

Suggested Plan for Final Review and Study 988

Summary 989

Part IX Appendixes

Glossary of Key Terms 991

Appendix A Answers to the “Do I Know This Already?” Quizzes and Q&A Sections 1002

Appendix B CCNP Security Implementing and Configuring Cisco Identity Services Engine (SISE 300-715) Exam Updates 1032

Appendix C Sample Switch Configurations 1034



Online Element

Appendix D Study Planner



TOC, 9780136642947, 9/30/2020


Need help? Get in touch