Which Two Fields Are Required in an ISE Native Supplicant Profile?
A company has a Cisco wireless network with Cisco ISE. The company wants to allow employees to use their personal mobile devices on the wireless network. The company wants to allow access to the network only if the devices meet certain criteria. To meet the requirement, the company asked a network engineer to create a native supplicant profile. Which two fields must be configured when the profile is created? (Choose two.)
Community Votes
100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This item tests whether you know the actual fields inside the ISE client-provisioning native supplicant profile — the trap is confusing supplicant-profile settings with WLC or controller-level settings such as WLC Name.
When Cisco ISE provisions personal mobile devices for BYOD, the native supplicant profile must define both the Allowed Protocol (PEAP/TLS) and the SSID Name. These two fields let the supplicant wizard install a working 802.1X profile on the employee device and bind it to the corporate WLAN.
Candidates often pick a made-up protocol pairing (Ms-CHAPv2/EAP-FAST or LEAP/EAP-TTLS) or choose WLC Name, because those terms appear elsewhere in wireless configuration, but the native supplicant profile only exposes a supported allowed-protocol list plus the target SSID.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Cisco ISE client provisioning, the native supplicant profile is the template that the supplicant provisioning wizard pushes to a Windows, macOS, iOS or Android endpoint so it can build a native 802.1X profile automatically. The two mandatory inputs are the authentication protocol the supplicant should negotiate and the wireless network it should apply to. The supported selection is PEAP/TLS (the option rendered as "Allowed Protocol (PEAP/TLS)"), which maps to the standard PEAPv0/MSCHAPv2 inner method with a server certificate, and the SSID Name, which is the corporate WLAN the device will join. Without the SSID, the generated profile would have nowhere to attach; without the protocol, the wizard cannot construct the EAP method chain. Together they satisfy the requirement of admitting only devices that complete 802.1X and meet the authorization conditions configured in ISE.Why the Other Options Are Wrong
Option B pairs MS-CHAPv2 with EAP-FAST, and option E pairs LEAP with EAP-TTLS; neither combination appears as a selectable value in the native supplicant profile's allowed-protocol drop-down, so they cannot be the answer. Option D, WLC Name, is not a supplicant-level field at all — the WLC that terminates the client's 802.1X session is determined by where the SSID is broadcast, not by anything the supplicant profile configures. Option C (SSID Name) is correct and must be paired with exactly one protocol option, which is why the answer is a two-letter set rather than a single letter.Community Comment Notes
claudio392 pointed straight at the Cisco ISE administration guide page on configuring client provisioning, which is the authoritative reference for this dialog. rrahim walked through the same logic in plain language, noting that PEAP/TLS "specifies the authentication protocols that are allowed for the supplicant profile" and that the SSID Name "specifies the SSID of the wireless network that the devices will connect to," so the provisioned device lands on the right WLAN. casterJR kept it short: the correct answer is AC. The unanimous AC vote (100%) matches the vendor documentation, so there is no reason to deviate from it.Official Reference
Exam Strategy
For BYOD provisioning questions, separate endpoint-side artifacts (supplicant profiles, certificates, authorization policies in ISE) from infrastructure-side settings (WLC name, interface, ACL) — the question usually asks about only one layer. Remember that a native supplicant profile always pairs one allowed protocol with one target SSID.
Frequently Asked Questions
Why is Allowed Protocol (LEAP/EAP-TTLS) not a valid native supplicant field?
The ISE native supplicant profile only offers supported allowed-protocol combinations such as PEAP/TLS; LEAP/EAP-TTLS is not a selectable value, so it cannot be configured there.
Why is WLC Name not required when creating the native supplicant profile?
The profile runs on the endpoint, which learns its controller from the SSID it joins; WLC identity is infrastructure-side and plays no part in the supplicant template.