Which combination of identity store choices would provide strong, layered authentication for a security-conscious organization managing both corporate-owned devices and a smaller set of privileged administrator accounts in Cisco ISE?
Correct Answer: Certificate-based (PKI) authentication for corporate-owned device machine authentication, combined with multifactor authentication (password plus OTP token) for privileged administrator accounts
Explanation: Certificate-based authentication for managed devices plus MFA for privileged accounts provides strong, layered security appropriate to each population, unlike a single shared password for everyone, disabling authentication entirely, misapplying certificate auth to guests, misapplying MFA to guests while leaving admins on single-factor, or using MAB (device-based, not identity-verifying) for privileged account access.
Correct Answer: Certificate-based (PKI) authentication for corporate-owned device machine authentication, combined with multifactor authentication (password plus OTP token) for privileged administrator accounts
Explanation: Certificate-based authentication for managed devices plus MFA for privileged accounts provides strong, layered security appropriate to each population, unlike a single shared password for everyone, disabling authentication entirely, misapplying certificate auth to guests, misapplying MFA to guests while leaving admins on single-factor, or using MAB (device-based, not identity-verifying) for privileged account access.