Which Authorization Profile Option Supports MSE Room-Based Wireless Access?

Configure policies including authentication and authorization profiles Implement CoA
Answer Correct answer: C — Select the Track Movement check box in the Cisco ISE Authorization Profile so ISE polls the MSE and issues CoA when a device changes patient room.

An engineer is deploying Cisco ISE into an existing wireless environment for a hospital. The requirement from the customer is that the WLC use Cisco ISE for Central Web Authentication. The company also has a Cisco MSE that is used with the WLC to restrict access to patient records over wireless to the room of the patient only. Which option must be selected in the Authorization Profile on Cisco ISE to support the integration?

  1. MAP Location
  2. Access Type
  3. Track Movement Correct Answer
  4. Service Template

Community Votes

C
75%
A
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can separate an ISE policy condition (MAP Location, taken from the MSE) from an Authorization Profile attribute (Track Movement) — the trap is choosing MAP Location because it is the attribute that visibly grants per-room access.

In Cisco ISE, per-room wireless authorization for a hospital using a Cisco MSE requires the Track Movement check box inside the Authorization Profile, while MAP Location is only evaluated as an authorization policy condition. This page explains why the answer to the profile-level question is Track Movement (C) rather than MAP Location.

Most learners choose MAP Location (A) because it is the attribute that actually restricts access to the patient's room, but MAP Location belongs in the authorization policy rule from the MSE integration, not in the Authorization Profile the question explicitly asks about.

Community Discussion (4 comments)

Cachaman 👍 1 Selected: C
Correct answer C For the authorization policy you choose MAP location For the Authorization profile you check Track Movement See below https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200196-Location-based-authorization-with-Mobili.html
ce1997d 👍 1 Selected: C
Map location is used in the authorization rule and policy to assign the correct profile for the location. Track movement is a CHECK box that you select in the AUTHORIZATION PROFILE to make sure users of have change of authorization as they roam. Both would need to be used to make the solution work but the correct answer is Track Movement
dawlims 👍 1 Selected: A
The Cisco ISE MSE:Map Location attribute allows users to be granted access based on their location. This is done by integrating the Cisco Identity Services Engine (ISE) with the Cisco Mobility Services Engine (MSE).
AliAhmed 👍 1 Selected: C
Answer: Travk movement To track the endpoint movement, check the Track Movement check box while creating an authorization profile. Cisco ISE will query the relevant MSE for the endpoint location every 5 minutes to verify if the location was changed.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Track Movement is the only one of the four options that is a selectable check box inside the Cisco ISE Authorization Profile, which is exactly what the question asks for. When it is checked, ISE registers the endpoint for location tracking with the integrated Cisco MSE and queries that MSE roughly every five minutes to see whether the endpoint has changed location. If the patient device roams into a different room, the change in location triggers a CoA and the endpoint is re-authorized against the MAP Location condition so the correct room-scoped profile is reapplied. Without Track Movement enabled in the profile, ISE never re-polls the MSE, so a device could keep access to the previous room's records after moving. Because the requirement is specifically MSE-driven room restriction on a WLC using Central Web Authentication, the profile-level switch that makes the location data actionable is Track Movement.

Why the Other Options Are Wrong

MAP Location (A) is a real and necessary piece of the overall solution, but it is consumed in the authorization policy rule as a condition (matched against the MSE-reported map/location attribute), not selected in the Authorization Profile — the question asks for a profile setting, so A is the classic near-miss. Access Type (B) is a valid Authorization Profile element (for example setting ACCESS_ACCEPT), but it has nothing to do with MSE location or CoA on roaming. Service Template (D) is not the ISE Authorization Profile mechanism used to bind MSE location data to a session; service/device-administration style concepts do not perform location tracking. Only Track Movement changes ISE's runtime behaviour toward the MSE, which is the integration the scenario requires.

Community Comment Notes

One commenter, Cachaman, draws the line cleanly, noting that MAP Location is chosen in the authorization policy whereas "For the Authorization profile you check Track Movement" and linking Cisco's location-based authorization with Mobility Services Engine documentation. ce1997d makes the same distinction, observing that both pieces are needed for the solution to work but that the profile check box is the one being asked about, so "the correct answer is Track Movement." AliAhmed reinforces the mechanics, explaining that checking Track Movement makes ISE query the relevant MSE for endpoint location every five minutes to verify whether the location changed. Only dawlims argues for MAP Location, correctly stating that the MSE MAP Location attribute grants access based on location, but that describes where the condition lives in the policy rather than what is configured in the Authorization Profile.

Official Reference

Exam Strategy

On ISE questions, first decide whether the stem is asking about a policy condition, an authorization policy rule, or an Authorization Profile attribute — the same word (location in this case) can appear in all three places. MAP Location is matched as a condition, while Track Movement is the profile switch that keeps that location current via MSE polling and CoA.

Frequently Asked Questions

Why is MAP Location not the answer if it restricts access per patient room?

MAP Location is evaluated as a condition in the authorization policy rule using data from the MSE integration. It cannot be selected inside the Authorization Profile, which is what this question asks about.

What does enabling Track Movement in the ISE Authorization Profile actually do?

ISE queries the integrated MSE for the endpoint's location about every five minutes and triggers a CoA when the location changes, re-applying the room-scoped authorization profile.

Related Analysis

← Back to 300-715 Study Guide