
CCIE Security
Domain 4Objective 9
4.9 Posture Assessment with Cisco ISE CCIE-SECURITY Practice Questions (Page 8)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
25%of the exam
Questions 36–40
- 36
A company is deploying Cisco ISE posture assessment for their Windows 10 endpoints. They want to ensure that only endpoints with the latest Windows updates and a running antivirus are granted full network access. The security team wants a solution that requires minimal user interaction and automatically enforces compliance. What should the administrator configure in Cisco ISE to meet these requirements?
Select an answer first - 37
An organization has a posture policy that requires endpoints to have the latest antivirus definitions. When an endpoint is non-compliant, ISE redirects the user to a remediation portal. However, the user reports that after updating the antivirus, they are still redirected to the portal. What should the administrator check first?
Select an answer first - 38
A company uses Cisco ISE to enforce posture compliance for Windows and Mac endpoints. They want to check that the Windows firewall is enabled and that the Mac has FileVault enabled. What is the best way to configure these checks in ISE?
Select an answer first - 39
A network administrator is troubleshooting why a specific Windows endpoint is not being assessed by Cisco ISE. The endpoint is able to authenticate and receive an IP address, but the posture assessment never starts. The administrator has verified that the posture policy is correctly assigned and the endpoint is in the correct authorization profile. What is the most likely cause?
Select an answer first - 40
A company has a posture policy that requires all endpoints to have the latest OS patches. However, some endpoints are running an older OS version that is no longer supported by the posture agent. The security team wants to allow these endpoints to access the network but with limited access, while still encouraging them to upgrade. What is the best approach in Cisco ISE?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.