To enable CWA for wireless guest access, the ISE engineer needs to configure the following steps on the ISE server: * Create a guest portal with the desired settings and appearance. * Create an authorization profile that references the guest portal and the DACL name for the Airespace ACL configured on the WLC. The DACL name must match the name of the ACL on the WLC exactly. The authorization profile also needs to have the common tasks of Web Redirection and Web Authentication enabled. * Create an authorization policy that matches the unauthenticated devices based on the MAC address or other criteria and applies the authorization profile created in the previous step. The DACL name is required for the WLC to apply the correct ACL to the guest endpoints and redirect them to the guest portal. Without the DACL name, the WLC will not know which ACL to use and may grant full guest access to the endpoints. Therefore, the correct answer is D. References := Some possible references are: * Central Web Authentication (CWA) for guests with ISE * Understand And Troubleshoot Central Web-Authentication (CWA) In Guest Anchor Set-Up * Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Release 17.3.0 - Guest Access