Implementing and Configuring Cisco Identity Services Engine Practice Tests 2021 Pass 300-715 with confidence! [Q11-Q32]

Share

Implementing and Configuring Cisco Identity Services Engine Practice Tests 2021 | Pass 300-715 with confidence!

Practice CCNP Security 300-715 exam. Online Exam Practice Tests with detailed explanations!


For more info about Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)

Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)

 

NEW QUESTION 11
Which two components are required for creating a Native Supplicant Profile within a BYOD flow? (Choose two)

  • A. Connection Type
  • B. Windows Settings
  • C. iOS Settings
  • D. Redirect ACL
  • E. Operating System

Answer: A,E

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010101.html#reference_21024A3B2B27427EAC78495E56962729

 

NEW QUESTION 12
Which command displays all 802.1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?

  • A. show authentication sessions interface Gi 1/0/x
  • B. show authentication sessions
  • C. show authentication sessions output
  • D. show authentication sessions interface Gi1/0/x output

Answer: A

Explanation:
Section: Policy Enforcement
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-xe-3se-3850-cr-book/sec-s1- xe-3se-3850-cr-book_chapter_01.html#wp3404908137

 

NEW QUESTION 13
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)

  • A. Firepower
  • B. Shell
  • C. WLC
  • D. IOS
  • E. ASA

Answer: B,C

Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide TACACS+ ProfileTACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets.
The TACACS+ profile definitions are split into two components:
* Common tasks
* Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)-Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
* Shell
* WLC
* Nexus
* Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.

 

NEW QUESTION 14
A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?

  • A. The certificate checks are not being conducted.
  • B. The AD join point is no longer connected.
  • C. The AD DNS response is slow.
  • D. The network devices ports are shut down.

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612

 

NEW QUESTION 15
A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?

  • A. The certificate checks are not being conducted.
  • B. The AD join point is no longer connected.
  • C. The AD DNS response is slow.
  • D. The network devices ports are shut down.

Answer: B

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612

 

NEW QUESTION 16
Which two ports do network devices typically use for CoA? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3
  • E. 4

Answer: A,E

Explanation:
Section: Profiler
Explanation/Reference: https://documentation.meraki.com/MR/Encryption_and_Authentication/ Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points

 

NEW QUESTION 17
An engineer is configuring web authentication and needs to allow specific protocols to permit DNS traffic.
Which type of access list should be used for this configuration?

  • A. extended ACL
  • B. reflexive ACL
  • C. standard ACL
  • D. numbered ACL

Answer: A

Explanation:
Section: Web Auth and Guest Services

 

NEW QUESTION 18
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.

Answer:

Explanation:

 

NEW QUESTION 19
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?

  • A. idle timeout
  • B. session timeout
  • C. termination-action
  • D. radius-server timeout

Answer: A

Explanation:
Explanation
When the inactivity timer is enabled, the switch monitors the activity from authenticated endpoints. When the inactivity timer expires, the switch removes the authenticated session. The inactivity timer for MAB can be statically configured on the switch port, or it can be dynamically assigned using the RADIUS Idle-Timeout attribute

 

NEW QUESTION 20
Refer to the exhibit.

An organization recently implemented network device administration using Cisco ISE. Upon testing the ability to access all of the required devices, a user in the Cisco ISE group IT Admins is attempting to login to a device in their organization's finance department but is unable to. What is the problem?

  • A. The finance location is not a condition in the policy set.
  • B. The authorization policy doesn't correctly grant them access to the finance devices.
  • C. The IT training rule is taking precedence over the IT Admins rule.
  • D. The authorization conditions wrongly allow IT Admins group no access to finance devices.

Answer: B

 

NEW QUESTION 21
Which use case validates a change of authorization?

  • A. Endpoints are created through device registration for the guests
  • B. An authenticated, wired EAP-capable endpoint is discovered
  • C. An endpoint profiling policy is changed for authorization policy.
  • D. An endpoint that is disconnected from the network is discovered

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html

 

NEW QUESTION 22
Which two values are compared by the binary comparison (unction in authentication that is based on Active Directory?

  • A. user-presented certificate and a certificate stored in Active Directory
  • B. subject alternative name and the common name
  • C. user-presented password hash and a hash stored in Active Directory
  • D. MS-CHAPv2 provided machine credentials and credentials stored in Active Directory

Answer: B

Explanation:
Reference:
Basic certificate checking does not require an identity source. If you want binary comparison checking for the certificates, you must select an identity source. If you select Active Directory as an identity source, subject and common name and subject alternative name (all values) can be used to look up a user. https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/ b_ise_admin_guide_sample_chapter_01110.html

 

NEW QUESTION 23
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.

Answer:

Explanation:

 

NEW QUESTION 24
An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate. What must be done in order to provide the CA this information?

  • A. Install the Root CA and intermediate CA.
  • B. Generate the CSR.
  • C. Download the intermediate server certificate.
  • D. Download the CA server certificate.

Answer: B

 

NEW QUESTION 25
A laptop was stolen and a network engineer added it to the block list endpoint identity group What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access?

  • A. Select DenyAccess within the authorization policy.
  • B. Ensure that access to port 8444 is allowed within the ACL.
  • C. Select DROP under If Auth fail within the authentication policy.
  • D. Ensure that access to port 8443 is allowed within the ACL.

Answer: C

 

NEW QUESTION 26
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.

Answer:

Explanation:

Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide Step 1 Choose Administration > System The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings tab.
Step 5
Click Save to save the node configuration.

 

NEW QUESTION 27
A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

  • A. NoCoA
  • B. Disconnect
  • C. Reauth
  • D. Port Bounce

Answer: A

Explanation:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design

 

NEW QUESTION 28

Refer to the exhibit. In which scenario does this switch configuration apply?

  • A. when allowing multiple IP phones to be connected
  • B. when passing IP phone authentication
  • C. when preventing users with hypervisor
  • D. when allowing a hub with multiple clients connected

Answer: D

Explanation:
Explanation
https://www.linkedin.com/pulse/mac-authentication-bypass-priyanka-kumari#:~:text=Multi%2Dauthentication%

 

NEW QUESTION 29
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen What is causing this issue?

  • A. The groups are not added to Cisco ISE under the AD join point
  • B. The groups are present but need to be manually typed as conditions
  • C. Cisco ISE only sees the built-in groups, not user created ones
  • D. Cisco ISE's connection to the AD join point is failing

Answer: A

Explanation:
Reference:
https://www.youtube.com/watch?v=0kuEZEo564s&ab_channel=CiscoISE-IdentityServicesEngine

 

NEW QUESTION 30
What is a characteristic of the UDP protocol?

  • A. UDP can detect when a server is down.
  • B. UDP offers information about a non-existent server
  • C. UDP can detect when a server is slow
  • D. UDP offers best-effort delivery

Answer: D

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html

 

NEW QUESTION 31
Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?

  • A. client
  • B. authenticator
  • C. EAP server
  • D. supplicant

Answer: D

Explanation:
https://www.oreilly.com/library/view/cisco-ise-for/9780133103632/ch16.html#:~:text=What%20is%20a%20supplicant%3F,networks%2C%20both%20wired%20and%20wireless.&text=The%20802.1X%20transactions%20are,Identity%20Services%20Engine%20(ISE).

 

NEW QUESTION 32
......

Get instant access to 300-715 practice exam questions: https://drive.google.com/open?id=1Y7kiSSqlE2OH2Ot6jJfgFX5U1SX0mNVh

The best 300-715 exam study material and preparation tool is here: https://www.validbraindumps.com/300-715-exam-prep.html