Which combination of authorization policy practices would provide accurate, least-privilege access control for a large organization with diverse user populations and device types connecting through Cisco ISE?
Correct Answer: Well-ordered rules from most specific to most general, conditions based on meaningful attributes such as identity group, device compliance, and location, appropriately scoped authorization profiles, and regular review of policy hit counts and live logs
Explanation: Well-ordered, specificity-based rules, meaningful conditions, appropriately scoped profiles, and ongoing review together support accurate least-privilege access control, unlike an unordered flat rule list, a single maximum-access rule for everyone, never reviewing profiles, irrelevant conditions, or disabling authorization logging.
Correct Answer: Well-ordered rules from most specific to most general, conditions based on meaningful attributes such as identity group, device compliance, and location, appropriately scoped authorization profiles, and regular review of policy hit counts and live logs
Explanation: Well-ordered, specificity-based rules, meaningful conditions, appropriately scoped profiles, and ongoing review together support accurate least-privilege access control, unlike an unordered flat rule list, a single maximum-access rule for everyone, never reviewing profiles, irrelevant conditions, or disabling authorization logging.