Which Two Fields Are Required in an ISE Native Supplicant Profile?

Implement BYOD and guest Implement client security on different wireless architectures and ISE
Answer Correct answer: A, C — Configure the Allowed Protocol (PEAP/TLS) and the SSID Name in the ISE native supplicant profile so employee devices get the right WLAN and 802.1X method.

A company has a Cisco wireless network with Cisco ISE. The company wants to allow employees to use their personal mobile devices on the wireless network. The company wants to allow access to the network only if the devices meet certain criteria. To meet the requirement, the company asked a network engineer to create a native supplicant profile. Which two fields must be configured when the profile is created? (Choose two.)

  1. Allowed Protocol (PEAP/TLS) Correct Answer
  2. Allowed Protocol (Ms-CHAPv2/ EAP-FAST)
  3. SSID Name Correct Answer
  4. WLC Name
  5. Allowed Protocol (LEAP/ EAP-TTLS)

Community Votes

AC
100%

100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests whether you know the actual fields inside the ISE client-provisioning native supplicant profile — the trap is confusing supplicant-profile settings with WLC or controller-level settings such as WLC Name.

When Cisco ISE provisions personal mobile devices for BYOD, the native supplicant profile must define both the Allowed Protocol (PEAP/TLS) and the SSID Name. These two fields let the supplicant wizard install a working 802.1X profile on the employee device and bind it to the corporate WLAN.

Candidates often pick a made-up protocol pairing (Ms-CHAPv2/EAP-FAST or LEAP/EAP-TTLS) or choose WLC Name, because those terms appear elsewhere in wireless configuration, but the native supplicant profile only exposes a supported allowed-protocol list plus the target SSID.

Community Discussion (3 comments)

rrahim 👍 1 Selected: AC
Allowed Protocol (PEAP/TLS): This field specifies the authentication protocols that are allowed for the supplicant profile. PEAP (Protected Extensible Authentication Protocol) and TLS (Transport Layer Security) are commonly used for secure wireless authentication. SSID Name: This field specifies the SSID (Service Set Identifier) of the wireless network that the devices will connect to. It ensures that the profile is applied to the correct wireless network.
casterJR 👍 1
Correct Answer is AC
claudio392 👍 4 Selected: AC
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_configure_client_provisioning.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Cisco ISE client provisioning, the native supplicant profile is the template that the supplicant provisioning wizard pushes to a Windows, macOS, iOS or Android endpoint so it can build a native 802.1X profile automatically. The two mandatory inputs are the authentication protocol the supplicant should negotiate and the wireless network it should apply to. The supported selection is PEAP/TLS (the option rendered as "Allowed Protocol (PEAP/TLS)"), which maps to the standard PEAPv0/MSCHAPv2 inner method with a server certificate, and the SSID Name, which is the corporate WLAN the device will join. Without the SSID, the generated profile would have nowhere to attach; without the protocol, the wizard cannot construct the EAP method chain. Together they satisfy the requirement of admitting only devices that complete 802.1X and meet the authorization conditions configured in ISE.

Why the Other Options Are Wrong

Option B pairs MS-CHAPv2 with EAP-FAST, and option E pairs LEAP with EAP-TTLS; neither combination appears as a selectable value in the native supplicant profile's allowed-protocol drop-down, so they cannot be the answer. Option D, WLC Name, is not a supplicant-level field at all — the WLC that terminates the client's 802.1X session is determined by where the SSID is broadcast, not by anything the supplicant profile configures. Option C (SSID Name) is correct and must be paired with exactly one protocol option, which is why the answer is a two-letter set rather than a single letter.

Community Comment Notes

claudio392 pointed straight at the Cisco ISE administration guide page on configuring client provisioning, which is the authoritative reference for this dialog. rrahim walked through the same logic in plain language, noting that PEAP/TLS "specifies the authentication protocols that are allowed for the supplicant profile" and that the SSID Name "specifies the SSID of the wireless network that the devices will connect to," so the provisioned device lands on the right WLAN. casterJR kept it short: the correct answer is AC. The unanimous AC vote (100%) matches the vendor documentation, so there is no reason to deviate from it.

Official Reference

Exam Strategy

For BYOD provisioning questions, separate endpoint-side artifacts (supplicant profiles, certificates, authorization policies in ISE) from infrastructure-side settings (WLC name, interface, ACL) — the question usually asks about only one layer. Remember that a native supplicant profile always pairs one allowed protocol with one target SSID.

Frequently Asked Questions

Why is Allowed Protocol (LEAP/EAP-TTLS) not a valid native supplicant field?

The ISE native supplicant profile only offers supported allowed-protocol combinations such as PEAP/TLS; LEAP/EAP-TTLS is not a selectable value, so it cannot be configured there.

Why is WLC Name not required when creating the native supplicant profile?

The profile runs on the endpoint, which learns its controller from the SSID it joins; WLC identity is infrastructure-side and plays no part in the supplicant template.

Related Analysis

← Back to 300-430 Study Guide