Pass Cisco Implementing and Configuring Cisco Identity Services Engine Exam in First Attempt Guaranteed Updated Dump from PracticeMaterial!
Pass 300-715 Exam with 210 Questions - Verified By PracticeMaterial
NEW QUESTION 102
When setting up profiling in an environment using Cisco ISE for network access control, an organization must use non-proprietary protocols for collecting the information at layer 2. Which two probes will provide this information without forwarding SPAN packets to Cisco ISE? {Choose two.)
- A. SNMP query probe
- B. DNS probe
- C. DHCP SPAN probe
- D. RADIUS probe
- E. NetFlow probe
Answer: A,D
Explanation:
Explanation
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design
NEW QUESTION 103
An engineer is configuring TACACS+ within Cisco ISE for use with a non-Cisco network device. They need to send special attributes in the Access-Accept response to ensure that the users are given the appropriate access. What must be configured to accomplish this'?
- A. dACLs to enforce the various access policies for the users
- B. TACACS+ command sets to provide appropriate access
- C. custom access conditions for defining the different roles
- D. shell profiles with custom attributes that define the various roles
Answer: D
NEW QUESTION 104
Which two Cisco ISE deployment models require two nodes configured with dedicated PAN and MnT personas? (Choose two.)
- A. two PSN nodes with one PxGrid node
- B. seven PSN nodes with one PxGrid node
- C. five PSN nodes with one PxGrid node
- D. three PSN nodes
- E. six PSN nodes
Answer: A,C
NEW QUESTION 105
What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?
- A. State attribute
- B. Event
- C. Class attribute
- D. Cisco-av-pair
Answer: D
Explanation:
Section: Profiler
Explanation/Reference:
Reference: https://community.cisco.com/t5/network-access-control/ise-airespace-acl-wlc-problem/td- p/2110491
NEW QUESTION 106
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE. The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- B. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- C. Conrm the authorization policies are correct using the test aaa authorization admin drop legacy command.
- D. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
Answer: D
Explanation:
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4b13ab285f51
NEW QUESTION 107
What is needed to configure wireless guest access on the network?
- A. WEBAUTH ACL for redirection
- B. Captive Portal Bypass turned on
- C. endpoint already profiled in ISE
- D. valid user account in Active Directory
Answer: B
NEW QUESTION 108
An organization is hosting a conference and must make guest accounts for several of the speakers attending.
The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
- A. Create an authorization rule denying sponsored guest access.
- B. Navigate to the Sponsor Portal and suspend the guest accounts.
- C. Create an authorization rule denying guest access.
- D. Navigate to the Guest Portal and delete the guest accounts.
Answer: C
NEW QUESTION 109
Refer to the exhibit.
A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server Which two commands should be run to complete the configuration? (Choose two)
- A. aaa authorization auth-proxy default group radius
- B. radius server vsa sand authentication
- C. radius-server attribute 8 include-in-access-req
- D. dot1x system-auth-control
- E. ip device tracking
Answer: B,C
NEW QUESTION 110
By default, which traffic does an 802.IX-enabled switch allow before authentication?
- A. traffic permitted in the port dACL on Cisco ISE
- B. traffic permitted in the default ACL on the switch
- C. all traffic
- D. no traffic
Answer: B
NEW QUESTION 111
Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE?
(Choose two).
- A. TCP 8906
- B. TCP 8443
- C. TCP 8905
- D. TCP 80
- E. TCP 443
Answer: B,C
NEW QUESTION 112
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.
Answer:
Explanation:
NEW QUESTION 113
Which two fields are available when creating an endpoint on the context visibility page of Cisco ISE? (Choose two.)
- A. IP Address
- B. Security Group Tag
- C. Policy Assignment
- D. Endpoint Family
- E. Identity Group Assignment
Answer: C,E
Explanation:
Section: Policy Enforcement
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/ b_ise_admin_guide_22_chapter_010101.html
NEW QUESTION 114
Which Cisco ISE service allows an engineer to check the compliance of endpoints before connecting to the network?
- A. qualys
- B. personas
- C. nexpose
- D. posture
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-
1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010110.html Posture is a service in Cisco Identity Services Engine (Cisco ISE) that allows you to check the state, also known as posture, of all the endpoints that are connecting to a network for compliance with corporate security policies. This allows you to control clients to access protected areas of a network.
NEW QUESTION 115
A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group.
Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?
- A. Create and manage guest user accounts.
- B. Configure authorization settings for guest users.
- C. Authenticate guest users to Cisco ISE.
- D. Keep track of guest user activities.
Answer: A
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION 116
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide Step 1 Choose Administration > System > Deployment.
The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click Edit.
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings tab.
Step 5
Click Save to save the node configuration.
NEW QUESTION 117
Which of these is not a method to obtain Cisco ISE profiling data?
- A. SNMP query
- B. active scans
- C. HTTP
- D. RADIUS
- E. DNS
- F. Netflow
Answer: B
NEW QUESTION 118
Which protocol must be allowed for a BYOD device to access the BYOD portal?
- A. HTTPS
- B. SMTP
- C. SSH
- D. HTTP
Answer: A
Explanation:
Section: BYOD
NEW QUESTION 119 
Refer to the exhibit. Which command is typed within the CLI of a switch to view the troubleshooting output?
- A. show authentication sessions method
- B. show authentication sessions mac 000e.84af.59af details
- C. show authentication registrations
- D. show authentication interface gigabitethernet2/0/36
Answer: B
Explanation:
Section: Policy Enforcement
NEW QUESTION 120
An engineer is implementing Cisco ISE and needs to configure 802.1X. The port settings are configured for port-based authentication. Which command should be used to complete this configuration?
- A. authentication port-control auto
- B. dot1x pae authenticator
- C. aaa authentication dot1x default group radius
- D. dot1x system-auth-control
Answer: C
NEW QUESTION 121
Which two components are required for creating a Native Supplicant Profile within a BYOD flow? (Choose two)
- A. Connection Type
- B. Operating System
- C. iOS Settings
- D. Redirect ACL
- E. Windows Settings
Answer: A,B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010101.html#reference_21024A3B2B27427EAC78495E56962729
NEW QUESTION 122
What is a requirement for Feed Service to work?
- A. Cisco ISE has Internet access to download feed update.
- B. Cisco ISE has a base license.
- C. Cisco ISE has access to an internal server to download feed update.
- D. TCP port 8080 must be opened between Cisco ISE and the feed server.
Answer: C
Explanation:
Section: Architecture and Deployment
NEW QUESTION 123
What is the minimum certainty factor when creating a profiler policy?
- A. the minimum number that a device certainty factor must reach to become a member of the profile
- B. the minimum number that a predefined condition provides
- C. the maximum number that a predefined condition provides
- D. the maximum number that a device certainty factor must reach to become a member of the profile
Answer: A
Explanation:
Section: Profiler
Explanation/Reference:
NEW QUESTION 124
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide Step 1 Choose Administration > System The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings tab.
Step 5
Click Save to save the node configuration.
NEW QUESTION 125
Refer to the exhibit.
A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server Which two commands should be run to complete the configuration? (Choose two)
- A. aaa authorization auth-proxy default group radius
- B. radius server vsa sand authentication
- C. radius-server attribute 8 include-in-access-req
- D. dot1x system-auth-control
- E. ip device tracking
Answer: B,C
NEW QUESTION 126
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen What is causing this issue?
- A. The groups are present but need to be manually typed as conditions
- B. Cisco ISE's connection to the AD join point is failing
- C. The groups are not added to Cisco ISE under the AD join point
- D. Cisco ISE only sees the built-in groups, not user created ones
Answer: C
Explanation:
Reference:
https://www.youtube.com/watch?v=0kuEZEo564s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION 127
......
Penetration testers simulate 300-715 exam: https://www.practicematerial.com/300-715-exam-materials.html
Free Test Engine For Implementing and Configuring Cisco Identity Services Engine Certification Exams: https://drive.google.com/open?id=1n-S3w9WxOh5qI5AzBuLeykhIW3UV-PpV

