[2023] 300-715 PDF Questions - Perfect Prospect To Go With ExamsTorrent Practice Exam
Cisco 300-715 Pdf Questions - Outstanding Practice To your Exam
NEW QUESTION # 43
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?
- A. DEVICE Device Type CONTAINS <SSID Name>
- B. Network Access NetworkDeviceName CONTAINS <SSID Name>
- C. Airespace Airespace-Wlan-ld CONTAINS <SSID Name>
- D. Radius Called-Station-ID CONTAINS <SSID Name>
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115734-ise-policies-ssid-00.ht
NEW QUESTION # 44
A policy is being created in order to provide device administration access to the switches on a network. There is a requirement to ensure that if the session is not actively being used, after 10 minutes, it will be disconnected. Which task must be configured in order to meet this requirement?
- A. idle time
- B. set attribute as
- C. session timeout
- D. monitor
Answer: A
NEW QUESTION # 45
Which use case validates a change of authorization?
- A. An authenticated, wired EAP-capable endpoint is discovered
- B. An endpoint that is disconnected from the network is discovered
- C. An endpoint profiling policy is changed for authorization policy.
- D. Endpoints are created through device registration for the guests
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html
NEW QUESTION # 46
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
NEW QUESTION # 47
Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.)
- A. updating of endpoint dACL
- B. endpoint profile transition from Unknown to Windows10-Workstation
- C. addition of endpoint to My Devices Portal
- D. endpoint profile transition from Apple-device to Apple-iPhone
- E. endpoint marked as lost in My Devices Portal
Answer: B,D
Explanation:
Section: Profiler
NEW QUESTION # 48
An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?
- A. HTTP probe
- B. RADIUS probe
- C. NetFlow probe
- D. network scan probe
Answer: A
NEW QUESTION # 49
Refer to the exhibit:
Which command is typed within the CU of a switch to view the troubleshooting output?
- A. show authentication interface gigabitethemet2/0/36
- B. show authentication registrations
- C. show authentication sessions mac 000e.84af.59af details
- D. show authentication sessions method
Answer: A
NEW QUESTION # 50
What does a fully distributed Cisco ISE deployment include?
- A. All Cisco ISE personas are sharing the same node.
- B. PAN and PSN on the same node while MnTs are on their own dedicated nodes.
- C. PAN and MnT on the same node while PSNs are on their own dedicated nodes.
- D. All Cisco ISE personas on their own dedicated nodes.
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_setup_cisco_ise.html
NEW QUESTION # 51
Drag and Drop Question
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.
Answer:
Explanation:
Explanation:
Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services. This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-
4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_011.html#ID57
NEW QUESTION # 52
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.
Answer:
Explanation:
Explanation
https://www.mbne.net/tech-notes/aaa-tacacs-radius
NEW QUESTION # 53
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this What should be done to enable this type of posture check?
- A. Enable the default application condition to identify the applications installed and validade the rewall app.
- B. Use the file registry condition to ensure that the firewal is installed and running appropriately.
- C. Use a compound condition to look for the Windows or Mac native firewall applications.
- D. Enable the default rewall condition to check for any vendor rewall application.
Answer: D
Explanation:
https://www.youtube.com/watch?v=6Kj8P8Hn7dY&t=109s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION # 54
Which use case validates a change of authorization?
- A. An authenticated, wired EAP-capable endpoint is discovered
- B. An endpoint that is disconnected from the network is discovered
- C. An endpoint profiling policy is changed for authorization policy.
- D. Endpoints are created through device registration for the guests
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html
NEW QUESTION # 55
Refer to the exhibit:
Refer to the exhibit. In which scenario does this switch configuration apply?
- A. when passing IP phone authentication
- B. when preventing users with hypervisor
- C. when allowing multiple IP phones to be connected
- D. when allowing a hub with multiple clients connected
Answer: D
Explanation:
https://www.linkedin.com/pulse/mac-authentication-bypass-priyanka-kumari#:~:text=Multi%2Dauthentication%20host%20mode%3A%20You,allows%20multiple%20source%20MAC%20addresses.
NEW QUESTION # 56
A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA Which action does the CoA perform?
- A. It applies the downloadable ACL provided in the CoA
- B. It terminates the client session
- C. It applies new permissions provided in the CoA to the client session.
- D. It triggers the NAD to reauthenticate the client
Answer: A
Explanation:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html
NEW QUESTION # 57
Which two features must be used on Cisco ISE to enable the TACACS. feature? (Choose two)
- A. Command Sets
- B. Server Sequence
- C. External TACACS Servers
- D. Enable Device Admin Service
- E. Device Administration License
Answer: D,E
NEW QUESTION # 58
An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate. What must be done in order to provide the CA this information?
- A. Download the CA server certificate.
- B. Download the intermediate server certificate.
- C. Generate the CSR.
- D. Install the Root CA and intermediate CA.
Answer: D
NEW QUESTION # 59
An organization is hosting a conference and must make guest accounts for several of the speakers attending. The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
- A. Create an authorization rule denying guest access.
- B. Navigate to the Guest Portal and delete the guest accounts.
- C. Create an authorization rule denying sponsored guest access.
- D. Navigate to the Sponsor Portal and suspend the guest accounts.
Answer: D
NEW QUESTION # 60
Which default endpoint identity group does an endpoint that does not match any profile in Cisco ISE become a member of?
- A. profiled
- B. unknown
- C. Endpoint
- D. white list
- E. blacklist
Answer: B
Explanation:
Explanation
If you do not have a matching profiling policy, you can assign an unknown profiling policy. The endpoint is therefore profiled as Unknown. The endpoint that does not match any profile is grouped within the Unknown identity group. The endpoint profiled to the Unknown profile requires that you create a profile with an attribute or a set of attributes collected for that endpoint.
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html
NEW QUESTION # 61
A network engineer has been tasked with enabling a switch to support standard web authentication for Cisco ISE. This must include the ability to provision for URL redirection on authentication Which two commands must be entered to meet this requirement? (Choose two)
- A. Ip http authentication
- B. Ip http secure-server
- C. Ip http server
- D. Ip http redirection
- E. Ip http secure-authentication
Answer: B,C
Explanation:
https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0111001.html
NEW QUESTION # 62
An administrator needs to connect ISE to Active Directory as an external authentication source and allow the proper ports through the firewall. Which two ports should be opened to accomplish this task? (Choose two)
- A. MSRPC 445
- B. HTTP 80
- C. HTTPS 443
- D. LDAP 389
- E. TELNET 23
Answer: A,D
NEW QUESTION # 63
Which two values are compared by the binary comparison (unction in authentication that is based on Active Directory?
- A. MS-CHAPv2 provided machine credentials and credentials stored in Active Directory
- B. subject alternative name and the common name
- C. user-presented certificate and a certificate stored in Active Directory
- D. user-presented password hash and a hash stored in Active Directory
Answer: B
Explanation:
Reference:
Basic certificate checking does not require an identity source. If you want binary comparison checking for the certificates, you must select an identity source. If you select Active Directory as an identity source, subject and common name and subject alternative name (all values) can be used to look up a user. https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/ b_ise_admin_guide_sample_chapter_01110.html
NEW QUESTION # 64
An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+ However, the administrator must restrict certain commands based on one of three user roles that require different commands How is this accomplished without creating too many objects using Cisco ISE?
- A. Create one shell profile and multiple command sets.
- B. Create one shell profile and one command set.
- C. Create multiple shell profiles and multiple command sets.
- D. Create multiple shell profiles and one command set
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_g
https://www.youtube.com/watch?v=IlZwB71Szog ab_channel=JasonMaynard
NEW QUESTION # 65
Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.)
- A. updating of endpoint dACL.
- B. addition of endpoint to My Devices Portal
- C. endpoint profile transition from Unknown to Windows 10-Workstation
- D. endpoint marked as lost in My Devices Portal
- E. endpoint profile transition from Aop.e-dev.ee to Apple-iPhone
Answer: C,E
NEW QUESTION # 66
A network engineer needs to deploy 802.1x using Cisco ISE in a wired network environment where thin clients download their system image upon bootup using PXE. For which mode must the switch ports be configured?
- A. low-impact
- B. closed
- C. monitor
- D. restricted
Answer: A
NEW QUESTION # 67
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
NEW QUESTION # 68
......
Online Questions - Outstanding Practice To your 300-715 Exam: https://troytec.examstorrent.com/300-715-exam-dumps-torrent.html