[Jan 27, 2022] Genuine 300-715 Exam Dumps New 2022 Cisco Pratice Exam
New 2022 Realistic 300-715 Dumps Test Engine Exam Questions in here
Exam Topics for Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)
The following will be practiced in CISCO 300-715 practice exam and CISCO 300-715 practice tests:
- Web Auth and guest services
- Network access device administration
- Architecture and deployment
- BYOD
- Policy enforcement
- Profiler
- Endpoint compliance
NEW QUESTION 60
How is policy services node redundancy achieved in a deployment?
- A. by deploying both primary and secondary node
- B. by enabling VIP
- C. by creating a node group
- D. by utilizing RADIUS server list on the NAD
Answer: A
NEW QUESTION 61
Which Cisco ISE service allows an engineer to check the compliance of endpoints before connecting to the network?
- A. qualys
- B. posture
- C. nexpose
- D. personas
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010110.html Posture is a service in Cisco Identity Services Engine (Cisco ISE) that allows you to check the state, also known as posture, of all the endpoints that are connecting to a network for compliance with corporate security policies. This allows you to control clients to access protected areas of a network.
NEW QUESTION 62
An engineer is configuring web authentication using non-standard ports and needs the switch to redirect traffic to the correct port.
Which command should be used to accomplish this task?
- A. aaa group server radius
- B. aaa group server radius proxy
- C. ip http port <port number>
- D. permit tcp any any eq <port number>
Answer: C
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION 63
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.
Answer:
Explanation:
NEW QUESTION 64
Which permission is common to the Active Directory Join and Leave operations?
- A. Set attributes on the Cisco ISE machine account
- B. Remove the Cisco ISE machine account from the domain.
- C. Search Active Directory to see if a Cisco ISE machine account already ex.sts.
- D. Create a Cisco ISE machine account in the domain if the machine account does not already exist
Answer: C
NEW QUESTION 65
What is a requirement for Feed Service to work?
- A. Cisco ISE has Internet access to download feed update.
- B. TCP port 8080 must be opened between Cisco ISE and the feed server.
- C. Cisco ISE has a base license.
- D. Cisco ISE has access to an internal server to download feed update.
Answer: D
Explanation:
Section: Architecture and Deployment
NEW QUESTION 66
A network administrator must configura endpoints using an 802 1X authentication method with EAP identity certificates that are provided by the Cisco ISE When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network Which EAP type must be configured by the network administrator to complete this task?
- A. EAP-FAST
- B. EAP-TLS
- C. EAP-TTLS
- D. EAP-PEAP-MSCHAPv2
Answer: B
Explanation:
https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/certificate-requirements-eap-tls-peap about EAP FAST
https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html
NEW QUESTION 67
A network administrator changed a Cisco ISE deployment from pilot to production and noticed that the JVM memory utilization increased significantly. The administrator suspects this is due to replication between the nodes What must be configured to minimize performance degradation?
- A. Enable the endpoint attribute filter
- B. Ensure that Cisco ISE is updated with the latest profiler feed update
- C. Review the profiling policies for any misconfiguration
- D. Change the reauthenticate interval.
Answer: A
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide
NEW QUESTION 68
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.
Answer:
Explanation:
NEW QUESTION 69
An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones The phones do not have the ability to authenticate via 802 1X Which command is needed on each switch port for authentication?
- A. mab
- B. enable network-authentication
- C. dot1x system-auth-control
- D. enable bypass-mac
Answer: A
Explanation:
Reference:
https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_aaa/configuration/15-2mt/sec-config-mab.html
NEW QUESTION 70
Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE?
(Choose two.)
- A. TCP 8443
- B. TCP 8905
- C. TCP 80
- D. TCP 8906
- E. TCP 443
Answer: A,B
Explanation:
Section: Endpoint Compliance
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/installation_guide/b_ise_InstallationGuide20/ Cisco_SNS_3400_Series_Appliance_Ports_Reference.html
NEW QUESTION 71
Which term refers to an endpoint agent that tries to join an 802.1X-enabled network?
- A. EAP server
- B. authenticator
- C. client
- D. supplicant
Answer: D
Explanation:
Section: Endpoint Compliance
NEW QUESTION 72
Which default endpoint identity group does an endpoint that does not match any profile in Cisco ISE become a member of?
- A. blacklist
- B. profiled
- C. unknown
- D. endpoint
- E. whitelist
Answer: C
Explanation:
Section: Profiler
Explanation/Reference: https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html
NEW QUESTION 73
What is a characteristic of the UDP protocol?
- A. UDP can detect when a server is down.
- B. UDP can detect when a server is slow
- C. UDP offers best-effort delivery
- D. UDP offers information about a non-existent server
Answer: C
Explanation:
https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html
NEW QUESTION 74
An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?
- A. MDM
- B. Client provisioning
- C. BYOD
- D. My devices
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html
NEW QUESTION 75
A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?
- A. The AD DNS response is slow.
- B. The certificate checks are not being conducted.
- C. The AD join point is no longer connected.
- D. The network devices ports are shut down.
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_
NEW QUESTION 76
What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?
- A. Class attribute
- B. Event
- C. State attribute
- D. Cisco-av-pair
Answer: D
NEW QUESTION 77
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.
Answer:
Explanation:
Explanation
Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services.
This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide
NEW QUESTION 78
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for one day When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
- A. The Endpoint Purge Policy is set to 30 days for guest devices
- B. The Guest Account Purge Policy is set to 15 days
- C. The length of access is set to 7 days in the Guest Portal Settings
- D. The RADIUS policy set for guest access is set to allow repeated authentication of the same device
Answer: A
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide
NEW QUESTION 79
Which three default endpoint identity groups does Cisco ISE create? (Choose three.)
- A. unknown
- B. endpoint
- C. allow list
- D. block list
- E. profiled
Answer: A,D,E
Explanation:
Section: Profiler
Explanation
Explanation/Reference: https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ ise10_man_identities.html#wp1203054
NEW QUESTION 80
An engineer is migrating users from MAB to 802.1X on the network. This must be done during normal business hours with minimal impact to users. Which CoA method should be used?
- A. Session Termination
- B. Port Bounce
- C. Port Shutdown
- D. Session Reauthentication
Answer: D
NEW QUESTION 81
Which Cisco ISE node does not support automatic failover?
- A. Monitoring node
- B. Admin node
- C. Policy Services node
- D. Inline Posture node
Answer: C
NEW QUESTION 82
What is a characteristic of the UDP protocol?
- A. UDP can detect when a server is slow.
- B. UDP offers information about a non-existent server.
- C. UDP offers best-effort delivery.
- D. UDP can detect when a server is down.
Answer: C
Explanation:
Section: Network Access Device Administration
Explanation/Reference:
NEW QUESTION 83
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
- A. block list
- B. unknown
- C. endpoint
- D. allow list
- E. profiled
Answer: B,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group. These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
Workstation-An identity group that contains all the profiled workstations on your network.
NEW QUESTION 84
......
Preparation Process
To get started with exam preparation, the applicants can take the Implementing & Configuring Cisco Identity Services Engine training course. It teaches them the way how to configure and utilize Cisco Identity Services Engine v2.4. It also focuses on the access and identity control policy platform, which simplifies the conveyance of consistent, highly secure access control across wireless, wired as well as VPN connections. In addition, this course can help the specialists to improve their knowledge and mastery of implementing and utilizing Cisco ISE (for instance, profiling services, policy enforcement, web authentication as well as guest access services, endpoint agreement services, BYOD, and TACACS+ device management). Furthermore, it can help the students to master their skills in streamlining security policy management as well as contributing to operational effectiveness. After completing this training option, the individuals will get 40 Continuing Education (CE) credits towards recertification.
BYOD: This topic checks the proficiency of the test takers in the following tasks:
- Setting the certificates for BYOD
- Setting block list/allow list
- Explaining the Cisco BYOD capabilities (these tasks can include usage cases and requirements, BYOD flow as well as solution components)
- Setting BYOD devices on-boarding utilizing internal CA along with Cisco switches and Cisco wireless local area network regulators
Grab latest Amazon 300-715 Dumps as PDF Updated: https://www.prep4king.com/300-715-exam-prep-material.html
Updated Official licence for 300-715 Certified by 300-715 Dumps PDF: https://drive.google.com/open?id=11jdup9xY2io4tSypB-K1VseUxJLGY4QA

