Best 300-715 Exam Dumps for the Preparation of Latest Exam Questions [Q56-Q71]

Share

Best 300-715 Exam Dumps for the Preparation of Latest Exam Questions

300-715 Actual Questions 100% Same Braindumps with Actual Exam!

NEW QUESTION # 56
Which type of identity store allows for creating single-use access credentials in Cisco ISE?

  • A. RSA SecurID
  • B. OpenLDAP
  • C. Local
  • D. PKI

Answer: A


NEW QUESTION # 57
When planning for the deployment of Cisco ISE, an organization's security policy dictates that they must use network access authentication via RADIUS. It also states that the deployment needs to provide an adequate amount of security and visibility for the hosts on the network.
Why should the engineer configure MAB in this situation?

  • A. MAB provides user authentication.
  • B. The devices in the network do not have a supplicant.
  • C. MAB provides the strongest form of authentication available.
  • D. The Cisco switches only support MAB.

Answer: B

Explanation:
Section: Endpoint Compliance


NEW QUESTION # 58
An administrator for a small network is configuring Cisco ISE to provide dynamic network access to users. Management needs Cisco ISE to not automatically trigger a CoA whenever a profile change is detected. Instead, the administrator needs to verify the new profile and manually trigger a CoA. What must be configuring in the profiler to accomplish this goal?

  • A. Port Bounce
  • B. No CoA
  • C. Reauth
  • D. Session Query

Answer: B

Explanation:
Explanation
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-policies


NEW QUESTION # 59
Which default endpoint identity group does an endpoint that does not match any profile in Cisco ISE become a member of?

  • A. white list
  • B. profiled
  • C. Endpoint
  • D. blacklist
  • E. unknown

Answer: E

Explanation:
Explanation
If you do not have a matching profiling policy, you can assign an unknown profiling policy. The endpoint is therefore profiled as Unknown. The endpoint that does not match any profile is grouped within the Unknown identity group. The endpoint profiled to the Unknown profile requires that you create a profile with an attribute or a set of attributes collected for that endpoint.
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html


NEW QUESTION # 60
An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE.
What must be configured within Cisco ISE to accomplish this goal?

  • A. Add the root certificate authority to the trust store and enable it for authentication.
  • B. Add an OCSP profile and configure the root certificate authority as secondary.
  • C. Create a certificate signing request and have the root certificate authority sign it.
  • D. Create an SCEP profile to link Cisco ISE with the root certificate authority.

Answer: D

Explanation:
Explanation
Ref:https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/116068-configure-pr


NEW QUESTION # 61
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.

Answer:

Explanation:


NEW QUESTION # 62
An engineer is using the low-impact mode for a phased deployment of Cisco ISE and is trying to connect to the network prior to authentication.
Which access will be denied in this deployment?

  • A. DHCP
  • B. EAP
  • C. DNS
  • D. HTTP

Answer: D

Explanation:
Section: Policy Enforcement
Explanation/Reference:


NEW QUESTION # 63
Which statement is not correct about the Cisco ISE Monitoring node?

  • A. The local collector agent collects logs locally from itself and from any NAD that is configured to send logs to the Policy Service node.
  • B. The local collector agent process runs only the Inline Posture node.
  • C. The local collector buffers transport the collected data to designated Cisco ISE Monitoring nodes as syslog; once Monitoring nodes are globally defined via Administration, ISE nodes automatically send logs to one or both of the configured Monitoring nodes.
  • D. Cisco ISE supports distributed log collection across all nodes to optimize local data collection, aggregation, and centralized correlation and storage.

Answer: B


NEW QUESTION # 64
An organization wants to enable web-based guest access for both employees and visitors The goal is to use a single portal for both user types Which two authentication methods should be used to meet this requirement? (Choose two )

  • A. 802 1X
  • B. LDAP
  • C. Certificate-based
  • D. MAC based
  • E. LOCAL

Answer: D,E


NEW QUESTION # 65
An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones. The phones do not have the ability to auto switch port for authentication?

  • A. dot1x system-auth-control
  • B. enable network-authentication
  • C. mab
  • D. enable bypass-MAC

Answer: A


NEW QUESTION # 66
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.

Answer:

Explanation:

Explanation

Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services.
This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide


NEW QUESTION # 67
An engineer must configure posture updates. The task is to ensure the latest set of predefined checks and operating system information is updated. The checks must take place regularly.
Where in the Cisco ISE interface would the engineer make the necessary changes to the compliance module?

  • A. Administration > System > Settings > Updates > Posture
  • B. Administration > System > Settings > Updates > Schedule
  • C. Administration > System > Settings > Posture > Updates > Schedule
  • D. Administration > System > Settings > Posture > Updates

Answer: D


NEW QUESTION # 68
What must match between Cisco ISE and the network access device to successfully authenticate endpoints?

  • A. SNMP version
  • B. certificate
  • C. profile
  • D. shared secret

Answer: D

Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_network_devices.html


NEW QUESTION # 69
An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal. Which condition must be used when configuring an authorization policy that sets DenyAccess permission?

  • A. Endpoint Identity Group is Blocklist, and the BYOD state is Lost.
  • B. Endpoint Identify Group is Blocklist, and the BYOD state is Pending.
  • C. Endpoint Identity Group is Blocklist, and the BYOD state is Reinstate.
  • D. Endpoint Identity Group is Blocklist, and the BYOD state is Registered.

Answer: D


NEW QUESTION # 70
A network is going through major hardware upgrades and is using Cisco ISE for network access control. Network devices are being added and removed regularly and the Cisco ISE administrators want to track new network devices. Which probe must be enabled to provide this visibility for Cisco ISE?

  • A. SNMP query
  • B. NetFlow
  • C. SNMP trap
  • D. DHCP SPAN

Answer: C


NEW QUESTION # 71
......

300-715 Study Material, Preparation Guide and PDF Download: https://passleader.testpassking.com/300-715-exam-testking-pass.html