
CCIE Security
Domain 4Objective 9
4.9 Posture Assessment with Cisco ISE CCIE-SECURITY Practice Questions (Page 4)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
25%of the exam
Questions 16–20
- 16
A company is deploying Cisco ISE posture assessment for a new Windows-based remote-access VPN. The security team wants to ensure that only endpoints with the latest Windows updates and a running antivirus can access the corporate network. They also want the posture agent to be automatically installed on endpoints that lack it. Which two actions must be performed in ISE to meet these requirements?
Select an answer first - 17
A small business is setting up Cisco ISE for the first time. They have a mix of Windows and Mac endpoints. They want to use the native posture agent for Windows and the AnyConnect posture agent for Mac. They also want to ensure that the correct agent is delivered to each endpoint automatically. What should they configure in ISE?
Select an answer first - 18
A hotel offers guest Wi-Fi to visitors. They want to provide internet access to guests, but they also want to ensure that guest devices are not infected with malware that could harm the network. They decide to use Cisco ISE posture assessment for guest access. What is the best way to implement this?
Select an answer first - 19
A network administrator is troubleshooting why some endpoints are not being assessed by Cisco ISE posture. The endpoints are running the posture agent, but they are not receiving any posture policy. What should the administrator check first?
Select an answer first - 20
A large enterprise has a complex ISE deployment with multiple posture policies. They have a posture policy for corporate Windows laptops that requires antivirus, encryption, and specific patches. Recently, they have been experiencing issues where some endpoints are incorrectly marked as non-compliant even though they meet all requirements. The security team suspects that the posture conditions are too strict or misconfigured. They want to identify the root cause without affecting production. What should they do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.