Which ISE Persona Makes Authorization Decisions from Threat and Vulnerability Attributes?
An engineer is configuring a new Cisco ISE node. The Cisco ISE must make authorization decisions based on the threat and vulnerability attributes received from the threat and vulnerability adapters. Which persona must be enabled?
Community Votes
57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which ISE persona actually performs authorization; the trap is choosing pxGrid because the threat and vulnerability adapters integrate through the pxGrid framework, even though pxGrid only transports data while the PSN decides.
Cisco ISE receives threat and vulnerability attributes from external adapters, but it is the Policy Service persona (PSN) that evaluates those attributes in the authorization policy and returns the access decision. This page explains why Policy Service — and not pxGrid — is the persona that must be enabled on the new ISE node.
Selecting pxGrid, because candidates associate threat and vulnerability adapters with pxGrid integration — but pxGrid is a publish/subscribe data-exchange persona, not the engine that evaluates policy and returns an authorization result.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Policy Service persona (PSN) is the persona that evaluates authentication and authorization policy in a Cisco ISE deployment and returns the access decision to the NAD. Threat and vulnerability adapters publish their endpoint attributes into ISE through the pxGrid framework, and those attributes become usable conditions inside an authorization policy set — but they only turn into an access decision when a Policy Service node evaluates the policy. Because the question states the node "must make authorization decisions based on the threat and vulnerability attributes," the persona that has to be enabled is Policy Service. A new node configured purely as a data-exchange or management node would never return an authorization result, no matter what attributes arrive. ## Why the Other Options Are Wrong pxGrid is the message-bus persona used to publish and subscribe context between ISE and third-party systems (including threat and vulnerability tools), and it does not evaluate policy or return access decisions itself. Administration covers deployment management, the GUI, certificates, licensing and configuration — it manages ISE but does not make session-level authorization decisions. Monitoring handles logging, reporting, live sessions, troubleshooting and dashboards; it consumes the results of policy evaluation rather than producing them. Each distractor is genuinely part of the threat-and-vulnerability story, which is exactly why the wording "make authorization decisions" must be mapped to the PSN. ## Community Comment Notes The community majority backed the Policy Service answer, with one learner writing that "pxGrid facilitates data sharing with external systems, not direct policy decision-making," and kerimeba adding that the PSN evaluates context such as identity, posture and threat/vulnerability information and then applies policy to determine access. A sizable minority voted for pxGrid, and Cachaman argued that the phrase "configuring a new Cisco ISE node" implies PSNs already exist in the deployment, so the new node's job would be pxGrid. That is a fair deployment argument, but the question explicitly ties the node to making authorization decisions, which is PSN work; pxGrid is the tempting distractor whenever adapters appear.Exam Strategy
Map the verb in the question to the persona: decides/authorizes = Policy Service, exchanges/shared context = pxGrid, manages/configures = Administration, logs/reports = Monitoring. Integrations such as threat and vulnerability adapters are usually flavor that pushes you toward pxGrid, so read the action the node must perform before picking.
Frequently Asked Questions
Why is pxGrid wrong when the threat and vulnerability adapters rely on it?
pxGrid only carries attributes between ISE and the external adapters; the authorization decision itself is evaluated by the Policy Service (PSN) persona, which is what the question asks for.
Does the new node need pxGrid enabled instead of Policy Service?
Adapter integration does use the pxGrid framework, but the question asks which persona makes the authorization decision, and that is always Policy Service.