Courseiva

CCNA Profiler Questions

41 questions · Profiler · All types, answers revealed

1
MCQmedium

When setting up a custom endpoint identity group for printers, what is the best practice for assigning devices to that group?

A.Manually add every printer MAC address to the group.
B.Use a Profiling Policy to automatically assign the device to the 'Printers' Identity Group.
C.Import a CSV file periodically.
D.Use an Authorization Policy to bypass profiling.
AnswerB

Automation via profiling policies ensures consistent grouping.

Why this answer

Using a profiling policy to automatically assign endpoints to a group based on matching conditions is the most scalable approach.

2
Multi-Selectmedium

Which THREE of the following are true regarding the Cisco ISE Profiler Feed Service?

Select 3 answers
A.It automatically assigns devices to groups.
B.It can be configured to update automatically on a schedule.
C.It downloads updated profiling policies from Cisco.
D.It is mandatory for all deployments.
E.It requires internet access for the PAN node.
AnswersB, C, E

Automated updates are a key feature.

Why this answer

The Feed Service provides updates, allows for manual/automatic updates, and ensures the list of profile policies is current.

3
Multi-Selecthard

Which TWO of the following are true regarding the 'Certainty Factor' in a Profiling Policy?

Select 2 answers
A.It is a global setting for the entire ISE deployment.
B.It allows ISE to weigh the importance of different attribute matches.
C.It is updated automatically by the Feed Service.
D.It can only be used with SNMP probes.
E.It determines whether a device should be assigned to an Identity Group.
AnswersB, E

It helps distinguish between weak and strong indicators.

Why this answer

The Certainty Factor is a weight applied to attributes to determine the confidence of a profile match, and it is configured within the profiling policy.

4
MCQmedium

Which probe is most effective for identifying the specific operating system and browser type of an endpoint connecting via a web portal?

A.HTTP probe
B.DHCP probe
C.MAC OUI probe
D.DNS probe
AnswerA

HTTP probe extracts the User-Agent header from HTTP requests.

Why this answer

The HTTP probe inspects the User-Agent string in HTTP headers, which identifies the browser and OS.

5
MCQmedium

A user reports that a device was incorrectly identified as a 'Cisco IP Phone' when it is actually a 'Cisco Access Point'. Which troubleshooting step should you take first?

A.Check the endpoint attributes in Context Visibility to see why it matched that policy.
B.Re-register the device.
C.Delete all profiling policies.
D.Restart the ISE node.
AnswerA

Identifying the source of the incorrect attribute match is the first step.

Why this answer

Reviewing the endpoint attributes in the 'Context Visibility' section will reveal which specific probes or attributes caused the incorrect profile match.

6
Multi-Selectmedium

Which THREE of the following are common reasons why an endpoint would be listed as 'Unknown' in Cisco ISE?

Select 3 answers
A.The device is connected to a non-Cisco switch.
B.The endpoint is not using 802.1X.
C.The endpoint has not generated enough traffic to trigger a probe.
D.The necessary probes are disabled on the PSN.
E.No profiling policies match the collected attributes.
AnswersC, D, E

A device must interact with the network to be profiled.

Why this answer

'Unknown' means the device hasn't been classified; this happens if no policies match, if probes are disabled, or if insufficient attributes are collected.

7
MCQmedium

Which probe is required to collect the 'User-Agent' string from a web browser to assist in profiling a device as a workstation?

A.HTTP
B.RADIUS
C.DHCP
D.DNS
AnswerA

The HTTP probe captures the User-Agent header from browser requests.

Why this answer

The HTTP probe is specifically designed to extract information from HTTP/HTTPS traffic, including the User-Agent string.

8
MCQeasy

When configuring a Profiling Policy, what happens if an endpoint matches multiple policies?

A.The system throws a configuration error.
B.The endpoint is assigned to the 'Multiple' group.
C.The first policy created is applied.
D.The system matches the most specific policy (highest number of conditions).
AnswerD

ISE evaluates conditions and applies the most granular match.

Why this answer

Cisco ISE matches profiling policies based on a 'most specific match' logic or order, but typically the most specific policy (highest logic depth) takes precedence.

9
MCQmedium

Which of the following describes the function of the 'Profiling Priority' setting?

A.It defines the order in which probes are executed.
B.It sets the order of endpoint group assignment.
C.It controls which PSN processes the policy.
D.It determines which policy is applied when multiple policies match.
AnswerD

Priority governs the selection of the winning policy.

Why this answer

When multiple profiling policies match, the one with the highest priority (lowest number) is applied.

10
MCQmedium

You are configuring a DHCP probe on a Cisco ISE node to identify endpoints. Which specific configuration step is required to ensure the ISE node receives DHCP traffic when the client and server are on a different subnet?

A.Configure a DHCP relay agent on the ISE node itself.
B.Enable DHCP Server mode on the Cisco ISE Profiling service.
C.Configure an IP helper-address on the Layer 3 device for the client VLAN pointing to the ISE node.
D.Enable DHCP Snooping on the ISE node interface.
AnswerC

IP helper-address is required to forward DHCP requests to the ISE node.

Why this answer

IP Helper-address must be configured on the default gateway to forward DHCP broadcasts to the ISE node acting as a probe.

11
MCQeasy

You need to create a custom profiling condition to identify printers based on their MAC OUI. Which menu path should you use to define this condition?

A.Administration > System > Profiling
B.Policy > Policy Elements > Conditions
C.Context Visibility > Endpoints
D.Policy > Profiling > Profiling Conditions
AnswerD

This is the correct path for creating, editing, and managing custom conditions.

Why this answer

Custom conditions are managed within the Policy > Profiling > Profiling Conditions section.

12
MCQmedium

You are configuring a custom profiling policy and notice that the 'Certainty Factor' is too low for the device to be assigned to the correct group. What is the purpose of the Certainty Factor in ISE?

A.To determine the priority of the profiling policy.
B.To force the device to re-authenticate.
C.To indicate the confidence level that the device is correctly profiled.
D.To limit the number of devices in an endpoint group.
AnswerC

It represents the cumulative score of matching profile conditions.

Why this answer

The Certainty Factor is a numerical value that increases as more matching conditions are met, ensuring a higher confidence in the device identity.

13
MCQmedium

When configuring an SNMP Query probe, why is it recommended to use SNMPv3 instead of SNMPv1/v2c?

A.SNMPv3 is the only version supported by ISE.
B.SNMPv3 is faster.
C.SNMPv3 provides authentication and encryption for the query.
D.SNMPv3 eliminates the need for a community string.
AnswerC

Security is the primary advantage.

Why this answer

SNMPv3 provides authentication and encryption, which are essential for security in enterprise networks.

14
MCQmedium

What is the function of the 'RADIUS Accounting' probe in the profiling process?

A.To encrypt the session.
B.To collect device attributes contained in RADIUS accounting packets.
C.To act as a RADIUS server.
D.To authenticate the device.
AnswerB

RADIUS accounting provides valuable session data.

Why this answer

It collects session information from the RADIUS traffic, providing start/stop and attribute data useful for device identification.

15
MCQmedium

Which component of the Cisco ISE Profiling architecture is responsible for comparing collected attributes against defined profiling policies?

A.Monitoring Node (MnT)
B.Feed Service
C.Administration Node (PAN)
D.Policy Service Node (PSN) Profiler Service
AnswerD

The Profiler service on the PSN is responsible for the policy matching logic.

Why this answer

The Profiler service on the PSN acts as the policy engine that matches attributes to policies.

16
MCQhard

You need to profile IoT devices that only support mDNS. Which probe should you enable?

A.mDNS probe
B.DHCP probe
C.SNMP Query probe
D.HTTP probe
AnswerA

mDNS probe specifically handles service discovery traffic.

Why this answer

The mDNS probe allows ISE to listen for Bonjour/mDNS service advertisements, which is critical for IoT discovery.

17
Multi-Selecthard

Which TWO of the following are necessary to successfully profile devices using the SNMP Query probe?

Select 2 answers
A.SNMP Write community string configured on the device.
B.LLDP-MED enabled on the endpoint.
C.Read access to the MIBs on the target device.
D.SNMP community string or credentials defined in ISE.
E.A static IP address on the target device.
AnswersC, D

The device must permit SNMP GET requests for the relevant MIBs.

Why this answer

SNMP requires read-only access to the device and the correct community string or credentials configured on the ISE PSN.

18
MCQmedium

You need to ensure that only specific ISE nodes perform the NMAP scan probe. Where is this configured?

A.Administration > System > Settings > Profiling Feed
B.Policy > Profiling > Profiling Policies
C.Administration > System > Deployment > [Node Name] > Profiling Configuration
D.Policy > Policy Elements > Results
AnswerC

Probes are enabled on a per-node basis in the deployment configuration.

Why this answer

Probe configuration, including which node collects which data, is handled in the Profiling Configuration tab for each PSN.

19
MCQeasy

Where do you view the 'Context Visibility' of endpoints in Cisco ISE?

A.Context Visibility > Endpoints
B.Administration > Network Resources
C.Policy > Endpoints
D.Operations > Context Visibility
AnswerA

This is the correct path for endpoint details.

Why this answer

The Context Visibility dashboard is located under the 'Context Visibility' menu in the ISE GUI.

20
MCQmedium

You have created a custom profiler condition that is not matching endpoints correctly. Where should you check the live authentication and profiling logs to verify if the attribute is being received by ISE?

A.Administration > System > Logging
B.Operations > RADIUS Livelogs
C.Policy > Profiling > Profiling Policies
D.Context Visibility > Endpoints
AnswerB

RADIUS Livelogs show the attributes received during the authentication process.

Why this answer

The RADIUS Live Logs or Profiling Live Logs under Operations are the standard locations to verify attribute collection.

21
MCQmedium

You are troubleshooting an issue where IP phones are not being profiled. The SNMP read community string on the switch does not match the one configured in ISE. What is the expected behavior?

A.The endpoint will be profiled based on the MAC OUI only.
B.The SNMP trap probe will still work.
C.The SNMP Query probe will fail to collect CDP/LLDP data from the switch.
D.ISE will automatically update the community string on the switch.
AnswerC

An invalid community string results in an authentication failure for SNMP requests.

Why this answer

If the SNMP community string is incorrect, ISE cannot query the switch, and the SNMP Query probe will fail to gather data.

22
MCQeasy

Which of the following is NOT a valid probe type in Cisco ISE?

A.SNMP Query
B.ICMP
C.DHCP
D.RADIUS
AnswerB

ICMP is not a supported profiling probe in ISE.

Why this answer

'ICMP' is not a dedicated probe type for profiling in the Cisco ISE interface; it is used for connectivity testing.

23
Multi-Selecthard

Which TWO of the following are true regarding the use of 'Endpoint Identity Groups' in Cisco ISE?

Select 2 answers
A.They are used to categorize endpoints for policy enforcement.
B.They can be used in Authorization Policy conditions.
C.They are used to define the user's role.
D.They are automatically purged every 24 hours.
E.An endpoint can belong to multiple groups simultaneously.
AnswersA, B

This is the main purpose of endpoint groups.

Why this answer

Endpoint Identity Groups allow for logical classification and are essential for mapping devices to specific authorization policies.

24
MCQmedium

When a new device connects, you notice it stays in the 'Unknown' profile state. You have confirmed the probes are active. What is the most likely step to fix this?

A.Increase the SNMP timeout.
B.Disable and re-enable the PSN service.
C.Create or update a Profiling Policy to match the collected attributes.
D.Delete the endpoint from the database.
AnswerC

The device needs a policy rule to match its attributes.

Why this answer

If the device is unknown, it likely does not match any existing policy rules; creating a new or adjusting an existing policy is the standard fix.

25
Multi-Selectmedium

Which THREE of the following are considered 'probes' in the Cisco ISE Profiling architecture?

Select 3 answers
A.ICMP Echo
B.DHCP
C.ARP Inspection
D.SNMP Query
E.HTTP
AnswersB, D, E

Standard profiling probe.

Why this answer

DHCP, SNMP, and HTTP are standard probes; RADIUS is also a probe type.

26
MCQmedium

Which attribute is used by the MAC OUI probe to determine the device manufacturer?

A.User-Agent string
B.IP Address
C.DHCP Client ID
D.MAC Address prefix (first 3 bytes)
AnswerD

The Organizationally Unique Identifier (OUI) is the first 3 bytes of the MAC.

Why this answer

The MAC OUI probe parses the first 3 bytes of the MAC address to identify the vendor.

27
MCQhard

You want to improve profiling accuracy for endpoints that do not send DHCP options. You decide to use SNMP Trap profiling. What is a critical prerequisite for this to function?

A.The network device must be configured to send SNMP traps to the ISE PSN IP address.
B.The endpoint must support SNMP agents.
C.The ISE node must have the SNMP Query probe enabled.
D.RADIUS Accounting must be disabled.
AnswerA

Without the destination set on the switch, the ISE node will never receive the traps.

Why this answer

SNMP Traps require the network device to be configured to send traps to the ISE node as a destination.

28
Multi-Selectmedium

Which TWO of the following are potential sources of information for the DHCP probe?

Select 2 answers
A.Layer 2 source MAC address.
B.IP Header Source Address.
C.DHCP Option 12 (Host Name)
D.DHCP Option 60 (Vendor Class Identifier)
E.DHCP Option 55 (Parameter Request List)
AnswersD, E

Option 60 is a primary source of device identification.

Why this answer

DHCP packets contain useful information in the Option fields, specifically the Vendor Class Identifier and the Parameter Request List.

29
MCQhard

You are troubleshooting a device that is stuck in the 'Unknown' profile state. You have confirmed that the DHCP probe is receiving packets. What is the next logical step to investigate the failure?

A.Increase the SNMP polling interval.
B.Check the attributes of the endpoint in Context Visibility.
C.Delete the endpoint from the database.
D.Restart the ISE node services.
AnswerB

This confirms if the DHCP data is being parsed into attributes recognized by the Profiling Policy.

Why this answer

Checking the endpoint's attributes in Context Visibility reveals exactly what the Profiler has learned. If the DHCP attributes are visible but the policy isn't matching, the policy logic is likely flawed.

30
Multi-Selecthard

Which TWO of the following are necessary to correctly configure a custom profiling condition based on DHCP attributes?

Select 2 answers
A.Enable HTTP profiling.
B.Configure a static IP on the endpoint.
C.Define a matching operator (e.g., equals, contains).
D.Clear the MAC address table on the switch.
E.Select the correct DHCP attribute from the attribute list.
AnswersC, E

The operator defines the logic of the match.

Why this answer

A custom condition requires selecting the specific DHCP attribute (e.g., Option 60) and defining the value to match.

31
Multi-Selecteasy

Which THREE of the following are standard probes available in Cisco ISE to gather device information?

Select 3 answers
A.SMTP
B.HTTP
C.FTP
D.SNMP Query
E.DHCP
AnswersB, D, E

HTTP is a primary probe.

Why this answer

ISE uses a variety of probes, including DHCP, HTTP, and SNMP, to collect device metadata.

32
MCQmedium

What is the purpose of the 'Endpoint Identity Group' in the context of profiling?

A.To manage authentication credentials.
B.To store device hardware serial numbers.
C.To define which PSN handles the device.
D.To classify devices for use in authorization policy rules.
AnswerD

Grouping enables policy-based access control.

Why this answer

Endpoint Identity Groups are used to organize devices into logical categories, which are then used in Authorization Policies.

33
Multi-Selecthard

Which TWO of the following are required to successfully profile a device using SNMP Query?

Select 2 answers
A.The device must have the SNMP Query probe enabled.
B.The device must support DHCP Option 150.
C.The device must have a static IP address.
D.The network device must be added to the ISE Network Devices list.
E.The device must be running an SNMP Agent.
AnswersA, D

The probe service must be active to perform the action.

Why this answer

SNMP query requires the network device to be added to ISE and the correct community string to be configured.

34
MCQmedium

You are configuring a device sensor on a Cisco switch to help with ISE profiling. What is the primary benefit of using Device Sensor?

A.It replaces the need for DHCP snooping.
B.It allows the switch to act as a RADIUS server.
C.It enables the switch to send collected device attributes to ISE via RADIUS accounting.
D.It increases the throughput of the switch.
AnswerC

This simplifies profiling by offloading data collection to the switch.

Why this answer

Device Sensor allows the switch to collect device information and send it to ISE using RADIUS Accounting, reducing the need for SNMP queries.

35
MCQhard

A administrator notices that certain medical devices are being intermittently profiled as 'Unknown' despite having a valid Profiling Policy. What is the most likely cause related to the Profiler Feed Service?

A.The endpoint identity group is full.
B.The Monitoring node is overloaded.
C.The device fingerprint signatures in the Profiler Feed Service are outdated.
D.The Profiler Feed Service is not enabled under Administration > System > Settings.
AnswerC

If the feed is not synced, ISE lacks the current OUI or pattern definitions to classify newer or specific device types.

Why this answer

The Feed Service updates the Profiler dictionary. If the OUI or device signature is not updated in the local dictionary, ISE cannot match the attributes gathered by the probes.

36
MCQhard

You are using the Feed Service to update your profiling policies. How can you ensure that custom profiling policies you have created are not overwritten during the update?

A.Custom policies are not affected by Feed Service updates.
B.Place custom policies in the system policy folder.
C.Export custom policies before every update.
D.Disable automatic updates.
AnswerA

The system architecture protects user-defined policies.

Why this answer

Cisco ISE Feed Service updates do not overwrite custom policies; they only add or update predefined policies in the 'Cisco' folder.

37
MCQhard

What is the impact of changing the 'Minimum Certainty Factor' in a Profiling Policy?

A.It requires more attributes to match before the policy is triggered.
B.It triggers an automatic purge of endpoint cache.
C.It disables the probe for that policy.
D.It changes the priority of the policy.
AnswerA

Increasing the threshold makes the condition harder to satisfy.

Why this answer

A higher threshold requires more matching attributes, making the profiling more restrictive and potentially less likely to match.

38
MCQhard

You are observing that an endpoint is being profiled as 'Unknown' even though it is clearly a Windows workstation. What is the most likely reason?

A.The device is using a static IP.
B.The necessary probes are not receiving enough attributes to match a policy.
C.The endpoint is not authenticated.
D.The endpoint has a firewall enabled.
AnswerB

Insufficient attributes mean no profile policy criteria are met.

Why this answer

If ISE has not received enough attributes to meet the threshold of a profiling policy, it remains 'Unknown'.

39
Multi-Selectmedium

Which THREE of the following items must be configured to ensure a successful SNMP Trap profiling implementation?

Select 3 answers
A.Add the network switch to the ISE Network Devices list.
B.Enable the SNMP Trap probe on the ISE PSN.
C.Enable HTTP probe.
D.Configure the network switch to send SNMP traps to the ISE PSN.
E.Configure DHCP Snooping.
AnswersA, B, D

ISE needs the device in its inventory to process the traps.

Why this answer

SNMP traps require the network device to be configured to send traps, the ISE PSN to listen for them, and the correct trap community or user context.

40
Multi-Selectmedium

Which THREE of the following are valid ways to trigger a profiling scan or update for an endpoint in Cisco ISE?

Select 3 answers
A.Manually trigger 'Re-profile' in Context Visibility.
B.Receive a new probe update for the endpoint.
C.Change the device's IP address.
D.Send a Change of Authorization (CoA) from a policy rule.
E.Modify the endpoint's MAC address.
AnswersA, B, D

This forces the profiler to re-evaluate collected data.

Why this answer

Endpoints can be re-profiled via manual refresh, CoA events, or changes in probe data.

41
Multi-Selectmedium

Which THREE of the following are valid methods for collecting endpoint attributes for profiling in Cisco ISE?

Select 3 answers
A.FTP inspection
B.SSH terminal login
C.HTTP User-Agent
D.DHCP Snooping/Helper
E.SNMP Query
AnswersC, D, E

HTTP probe collects browser information.

Why this answer

The probes that gather data include DHCP, SNMP, and HTTP.

Ready to test yourself?

Try a timed practice session using only Profiler questions.