300-715 Dumps 2022 - New Cisco 300-715 Exam Questions
Free 300-715 braindumps download (300-715 exam dumps Free Updated)
NEW QUESTION 54
An organization is migrating its current guest network to Cisco ISE and has 1000 guest users in the current database There are no resources to enter this information into the Cisco ISE database manually. What must be done to accomplish this task effciently?
- A. Use a CSV file to import the guest accounts
- B. Use a JSON fie to automate the migration of guest accounts
- C. Use SOL to link me existing database to Ctsco ISE
- D. Use an XML file to change the existing format to match that of Cisco ISE
Answer: B
Explanation:
https://www.youtube.com/watch?v=DNYaFl-8zWk&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION 55
Which profiling probe collects the user-agent string?
- A. AD
- B. HTTP
- C. DHCP
- D. NMAP
Answer: B
NEW QUESTION 56
During BYOD flow, where does a Microsoft Windows PC download the Network Setup Assistant?
- A. Cisco App Store
- B. Microsoft App Store
- C. Native OTA functionality
- D. Cisco ISE directly
Answer: D
Explanation:
Section: BYOD
Explanation/Reference: https://ciscocustomer.lookbookhq.com/iseguidedjourney/BYOD-configuration
NEW QUESTION 57
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?
- A. Network Access NetworkDeviceName CONTAINS <SSID Name>
- B. Radius Called-Station-ID CONTAINS <SSID Name>
- C. Airespace Airespace-Wlan-ld CONTAINS <SSID Name>
- D. DEVICE Device Type CONTAINS <SSID Name>
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115734-ise-policies-ssid-00.html
NEW QUESTION 58
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide Step 1 Choose Administration > System > Deployment.
The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click Edit.
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings
Step 5
Click Save to save the node configuration.
NEW QUESTION 59
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?
- A. The primary node becomes standalone
- B. The secondary node restarts.
- C. The primary node restarts
- D. Both nodes restart.
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/installation_guide/ise_install_guide/ise_deploy.html if your deployment has two nodes and you deregister the secondary node, both nodes in this primary-secondary pair are restarted. (The former primary and secondary nodes become standalone.)
NEW QUESTION 60
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?
- A. Guest
- B. Client Provisioning
- C. BYOD
- D. Blacklist
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/ BY OD_Design_Guide/Managing_Lost_or_Stolen_Device.html#90273 The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
Blackhole WiFi Access
Blackhole Wired Access
NEW QUESTION 61
A laptop was stolen and a network engineer added it to the block list endpoint identity group What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access?
- A. Select DenyAccess within the authorization policy.
- B. Select DROP under If Auth fail within the authentication policy.
- C. Ensure that access to port 8443 is allowed within the ACL.
- D. Ensure that access to port 8444 is allowed within the ACL.
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010000.html
NEW QUESTION 62
An organization wants to standardize the 802 1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide What must be configured to accomplish this task?
- A. port security on the switch based on the client's information
- B. extended access-list on the switch for the client
- C. security group tag within the authorization policy
- D. dynamic access list within the authorization profile
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_sga_pol.html#
NEW QUESTION 63
Which two fields are available when creating an endpoint on the context visibility page of Cisco IS? (Choose two )
- A. Security Group Tag
- B. Endpoint Family
- C. IP Address
- D. Identity Group Assignment
- E. Policy Assignment
Answer: B,E
NEW QUESTION 64
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out Which configuration is causing this behavior?
- A. All of the nodes are actively being synched.
- B. All of the nodes participate in the PAN auto failover.
- C. One of the nodes is the Primary PAN
- D. One of the nodes is an active PSN.
Answer: C
NEW QUESTION 65
Which two features must be used on Cisco ISE to enable the TACACS. feature? (Choose two)
- A. Server Sequence
- B. Device Admin Service
- C. External TACACS Servers
- D. Device Administration License
- E. Command Sets
Answer: B,D
NEW QUESTION 66
Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?
- A. supplicant
- B. EAP server
- C. authenticator
- D. client
Answer: A
Explanation:
Reference:
https://www.oreilly.com/library/view/cisco-ise-for/9780133103632/ch16.html#:~:text=What%20is%20a%20supplicant%3F,networks%2C%20both%20wired%20and%20wireless.&text=The%20802.1X%20transactions%20are,Identity%20Services%20Engine%20(ISE).
NEW QUESTION 67
A network engineer has been tasked with enabling a switch to support standard web authentication for Cisco ISE. This must include the ability to provision for URL redirection on authentication Which two commands must be entered to meet this requirement? (Choose two)
- A. Ip http secure-server
- B. Ip http secure-authentication
- C. Ip http redirection
- D. Ip http authentication
- E. Ip http server
Answer: A,E
Explanation:
https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0111001.html
NEW QUESTION 68
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles? (Choose two.)
- A. Firepower
- B. Shell
- C. IOS
- D. WLC
- E. ASA
Answer: B,D
Explanation:
Section: Network Access Device Administration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2--1/admin_guide/b_ise_admin_guide_21/ b_ise_admin_guide_20_chapter_0100010.html
NEW QUESTION 69
......
Verified 300-715 dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://www.real4prep.com/300-715-exam.html
300-715 Dumps for Pass Guaranteed - Pass 300-715 Exam: https://drive.google.com/open?id=1oPS-2FnipmB6o0QdL-ci_iC1q4u78jA0