[Dec-2021] 300-715 Certification with Actual Questions from ValidBraindumps [Q68-Q90]

Share

[Dec-2021] 300-715  Certification with Actual Questions from ValidBraindumps

Updated 300-715 Dumps PDF - 300-715 Real Valid Brain Dumps With 153 Questions!


What is the cost of Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)

  • Length of Examination: 90 minutes
  • Format: Multiple choices, multiple answers
  • Number of Questions: 90-105
  • Passing Score: 70%

 

NEW QUESTION 68
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.

Answer:

Explanation:

Explanation

Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services.
This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide

 

NEW QUESTION 69
Which two methods should a sponsor select to create bulk guest accounts from the sponsor portal? (Choose two )

  • A. Daily
  • B. Random
  • C. Known
  • D. Monthly
  • E. Imported

Answer: B,E

 

NEW QUESTION 70
Which two default endpoint identity groups does cisco ISE create? (Choose two )

  • A. Unknown
  • B. end point
  • C. profiled
  • D. whitelist
  • E. blacklist

Answer: C,E

Explanation:
Explanation
Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide

 

NEW QUESTION 71
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

  • A. Blacklist
  • B. BYOD
  • C. Guest
  • D. Client Provisioning

Answer: A

Explanation:
Section: BYOD
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/ b_ise_admin_guide_sample_chapter_010000.html

 

NEW QUESTION 72
What is the minimum certainty factor when creating a profiler policy?

  • A. the maximum number that a predefined condition provides
  • B. the minimum number that a device certainty factor must reach to become a member of the profile
  • C. the minimum number that a predefined condition provides
  • D. the maximum number that a device certainty factor must reach to become a member of the profile

Answer: B

Explanation:
Section: Profiler
Explanation/Reference:

 

NEW QUESTION 73
Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE?
(Choose two).

  • A. TCP 8905
  • B. TCP 8906
  • C. TCP 80
  • D. TCP 8443
  • E. TCP 443

Answer: A,C

 

NEW QUESTION 74
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this What should be done to enable this type of posture check?

  • A. Use a compound condition to look for the Windows or Mac native firewall applications.
  • B. Enable the default rewall condition to check for any vendor rewall application.
  • C. Use the file registry condition to ensure that the firewal is installed and running appropriately.
  • D. Enable the default application condition to identify the applications installed and validade the rewall app.

Answer: B

Explanation:
https://www.youtube.com/watch?v=6Kj8P8Hn7dY&t=109s&ab_channel=CiscoISE-IdentityServicesEngine

 

NEW QUESTION 75
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.

Answer:

Explanation:

 

NEW QUESTION 76
What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?

  • A. central web authentication
  • B. posture
  • C. MAB
  • D. profiling

Answer: B

 

NEW QUESTION 77
What is a function of client provisioning?

  • A. Client provisioning checks a dictionary attribute with a value.
  • B. Client provisioning ensures that endpoints receive the appropriate posture agents.
  • C. Client provisioning checks the existence, date, and versions of the file on a client.
  • D. Client provisioning ensures an application process is running on the endpoint.

Answer: B

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_client_prov.html#:~:text=After%20Cisco%20ISE%20classifies%20a,packages%20and%20profiles%2C%20if%20necessary.

 

NEW QUESTION 78
Which two endpoint compliance statuses are possible? (Choose two.)

  • A. valid
  • B. known
  • C. unknown
  • D. compliant
  • E. invalid

Answer: C,D

 

NEW QUESTION 79
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)

  • A. WLC
  • B. Shell
  • C. ASA
  • D. IOS
  • E. Firepower

Answer: A,B

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_0100010.html TACACS+ Profile TACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets. The TACACS+ profile definitions are split into two components:
Common tasks
Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)-Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
Shell
WLC
Nexus
Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.

 

NEW QUESTION 80
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

  • A. Blacklist
  • B. BYOD
  • C. Guest
  • D. Client Provisioning

Answer: A

Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Desig The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
* Blackhole WiFi Access
* Blackhole Wired Access

 

NEW QUESTION 81
Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )

  • A. Device Administration License
  • B. Server Sequence
  • C. Command Sets
  • D. External TACACS Servers
  • E. Device Admin Service

Answer: A,E

 

NEW QUESTION 82
An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE.
What must be configured within Cisco ISE to accomplish this goal?

  • A. Add the root certificate authority to the trust store and enable it for authentication.
  • B. Create a certificate signing request and have the root certificate authority sign it.
  • C. Add an OCSP profile and configure the root certificate authority as secondary.
  • D. Create an SCEP profile to link Cisco ISE with the root certificate authority.

Answer: D

 

NEW QUESTION 83
An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the used to accomplish this task?

  • A. policy service
  • B. monitoring
  • C. primary policy administrator
  • D. pxGrid

Answer: B

 

NEW QUESTION 84
Which use case validates a change of authorization?

  • A. An authenticated, wired EAP-capable endpoint is discovered
  • B. An endpoint that is disconnected from the network is discovered
  • C. Endpoints are created through device registration for the guests
  • D. An endpoint profiling policy is changed for authorization policy.

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html

 

NEW QUESTION 85
Refer to the exhibit:

Which command is typed within the CU of a switch to view the troubleshooting output?

  • A. show authentication sessions mac 000e.84af.59af details
  • B. show authentication registrations
  • C. show authentication interface gigabitethemet2/0/36
  • D. show authentication sessions method

Answer: A

 

NEW QUESTION 86
A policy is being created in order to provide device administration access to the switches on a network. There is a requirement to ensure that if the session is not actively being used, after 10 minutes, it will be disconnected. Which task must be configured in order to meet this requirement?

  • A. session timeout
  • B. set attribute as
  • C. idle time
  • D. monitor

Answer: C

 

NEW QUESTION 87
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?

  • A. Radius Called-Station-ID CONTAINS <SSID Name>
  • B. DEVICE Device Type CONTAINS <SSID Name>
  • C. Airespace Airespace-Wlan-ld CONTAINS <SSID Name>
  • D. Network Access NetworkDeviceName CONTAINS <SSID Name>

Answer: A

Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115734-ise-policies-ssid-00.ht

 

NEW QUESTION 88
Which permission is common to the Active Directory Join and Leave operations?

  • A. Set attributes on the Cisco ISE machine account.
  • B. Create a Cisco ISE machine account in the domain if the machine account does not already exist.
  • C. Search Active Directory to see if a Cisco ISE machine account already exists.
  • D. Remove the Cisco ISE machine account from the domain.

Answer: C

Explanation:
Section: Policy Enforcement

 

NEW QUESTION 89
What should be considered when configuring certificates for BYOD?

  • A. An Android endpoint uses EST whereas other operation systems use SCEP for enrollment
  • B. The SAN field is populated with the end user name
  • C. An endpoint certificate is mandatory for the Cisco ISE BYOD
  • D. The CN field is populated with the endpoint host name.

Answer: C

 

NEW QUESTION 90
......

Pass Your 300-715 Exam Easily With 100% Exam Passing Guarantee: https://www.validbraindumps.com/300-715-exam-prep.html

100% Free 300-715 Exam Dumps Use Real CCNP Security Dumps: https://drive.google.com/open?id=12zHkIiyFykgDqMYDhuXM3OWINLoqTgh4