[Feb-2023] 300-715 Dumps are Available for Instant Access from Test4Engine
Study resources for the Valid 300-715 Braindumps!
A valuable & challenging Cisco exam that leads to two different Cisco certifications is test 300-715 SISE or Executing & Configuring Cisco Identity Services Engine.
NEW QUESTION 13
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?
- A. DEVICE Device Type CONTAINS <SSID Name>
- B. Radius Called-Station-ID CONTAINS <SSID Name>
- C. Network Access NetworkDeviceName CONTAINS <SSID Name>
- D. Airespace Airespace-Wlan-ld CONTAINS <SSID Name>
Answer: C
NEW QUESTION 14
An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the used to accomplish this task?
- A. primary policy administrator
- B. pxGrid
- C. policy service
- D. monitoring
Answer: D
NEW QUESTION 15
An engineer is using Cisco ISE and configuring guest services to allow wireless devices to access the network.
Which action accomplishes this task?
- A. Create the redirect ACL on the WLC and add it to the WLC policy.
- B. Create the redirect ACL on Cisco ISE and add it to the Cisco ISE Policy.
- C. Create the redirect ACL on the WLC and add it to the Cisco ISE policy.
- D. Create the redirect ACL on Cisco ISE and add it to the WLC policy.
Answer: C
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION 16
Which two probes must be enabled for the ARP cache to function in the Cisco ISE profile service so that a user can reliably bind the IP address and MAC addresses of endpoints? (Choose two.)
- A. NetFlow
- B. SNMP
- C. DHCP
- D. HTTP
- E. RADIUS
Answer: C,E
Explanation:
Cisco ISE implements an ARP cache in the profiling service, so that you can reliably map the IP addresses and the MAC addresses of endpoints. For the ARP cache to function, you must enable either the DHCP probe or the RADIUS probe. The DHCP and RADIUS probes carry the IP addresses and the MAC addresses of endpoints in the payload data. The dhcp-requested address attribute in the DHCP probe and the Framed-IP-address attribute in the RADIUS probe carry the IP addresses of endpoints, along with their MAC addresses, which can be mapped and stored in the ARP cache.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html
NEW QUESTION 17
An administrator connects an HP printer to a dot1x enable port, but the printer in not accessible Which feature must the administrator enable to access the printer?
- A. MAC authentication bypass
- B. change of authorization
- C. TACACS authentication
- D. RADIUS authentication
Answer: A
Explanation:
https://community.cisco.com/t5/network-access-control/ise-for-printer-security/m-p/3933216
NEW QUESTION 18
An administrator is troubleshooting an endpoint that is supposed to bypass 802 1X and use MAB. The endpoint is bypassing 802.1X and successfully getting network access using MAB. however the endpoint cannot communicate because it cannot obtain an IP address. What is the problem?
- A. The endpoint is using the wrong protocol to authenticate with Cisco ISE.
- B. An AC I on the port is blocking HTTP traffic
- C. The 802.1 X timeout period is too long.
- D. The DHCP probe for Cisco ISE is not working as expected.
Answer: C
NEW QUESTION 19
What must be configured on the Cisco ISE authentication policy for unknown MAC addresses/identities for successful authentication?
- A. drop
- B. reject
- C. pass
- D. continue
Answer: D
Explanation:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html
NEW QUESTION 20
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE. The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- B. Confirm the authorization policies are correct using the test aaa authorization admin drop legacy command.
- C. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- D. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
Answer: D
Explanation:
Reference:
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4b13ab285f51
NEW QUESTION 21
An organization is adding new profiling probes to the system to improve profiling on Oseo ISE The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected What must be configured on the network device to accomplish this goal?
- A. WCCP
- B. ARP
- C. SNMP
- D. ICMP
Answer: C
Explanation:
https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-790343135
NEW QUESTION 22
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two )
- A. policy service
- B. publisher
- C. administration
- D. primary
- E. subscriber
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html
NEW QUESTION 23
An administrator needs to allow guest devices to connect to a private network without requiring usernames and passwords. Which two features must be configured to allow for this? (Choose two.)
- A. self-registered guest portal
- B. central WebAuth
- C. hotspot guest portal
- D. device registration WebAuth
- E. local WebAuth
Answer: C,D
NEW QUESTION 24
What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?
- A. MAB
- B. posture
- C. central web authentication
- D. profiling
Answer: B
NEW QUESTION 25
Select and Place
Answer:
Explanation:
NEW QUESTION 26
Drag the descriptions on the left onto the components of 802.1X on the right.
Answer:
Explanation:
NEW QUESTION 27
An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node.
Which persona should be configured with the largest amount of storage in this environment?
- A. Primary Administration
- B. policy Services
- C. Platform Exchange Grid
- D. Monitoring and Troubleshooting
Answer: D
NEW QUESTION 28
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?
- A. Blacklist
- B. Guest
- C. Client Provisioning
- D. BYOD
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/Managing_Lost_or_Stolen_Device.html#90273 The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
Blackhole WiFi Access
Blackhole Wired Access
NEW QUESTION 29
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two )
- A. policy service
- B. publisher
- C. administration
- D. primary
- E. subscriber
Answer: A,C
NEW QUESTION 30
Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )
- A. External TACACS Servers
- B. Device Administration License
- C. Device Admin Service
- D. Command Sets
- E. Server Sequence
Answer: B,C
NEW QUESTION 31
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this What should be done to enable this type of posture check?
- A. Use a compound condition to look for the Windows or Mac native firewall applications.
- B. Enable the default application condition to identify the applications installed and validade the firewall app.
- C. Enable the default firewall condition to check for any vendor firewall application.
- D. Use the file registry condition to ensure that the firewal is installed and running appropriately.
Answer: C
Explanation:
https://www.youtube.com/watch?v=6Kj8P8Hn7dY&t=109s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION 32
What is an advantage of using EAP-TLS over EAP-MS-CHAPv2 for client authentication?
- A. EAP-TLS uses multiple forms of authentication, while EAP-MS-CHAPv2 only uses one.
- B. EAP-TLS uses a device certificate for authentication to enhance security, while EAP-MS-CHAPv2 does not.
- C. EAP-TLS uses a username and password for authentication to enhance security, while EAP-MS-CHAPv2 does not.
- D. EAP-TLS secures the exchange of credentials, while EAP-MS-CHAPv2 does not.
Answer: B
NEW QUESTION 33
......
Updated 300-715 Tests Engine pdf - All Free Dumps Guaranteed: https://www.test4engine.com/300-715_exam-latest-braindumps.html
Latest CCNP Security 300-715 Actual Free Exam Questions: https://drive.google.com/open?id=1CvePLKMxUBpsi3AQf-ko4ecjW4fZIYon