[Nov-2022] Latest Cisco 300-715 Certification Practice Test Questions [Q120-Q136]

Share

[Nov-2022] Latest Cisco 300-715 Certification Practice Test Questions

Verified 300-715 Dumps Q&As - 1 Year Free & Quickly Updates

NEW QUESTION 120
An administrator has added a new Cisco ISE PSN to their distributed deployment. Which two features must the administrator enable to accept authentication requests and profile the endpoints correctly, and add them to their respective endpoint identity groups? (Choose two )

  • A. Posture Services
  • B. Radius Service
  • C. Profiling Services
  • D. Session Services
  • E. Endpoint Attribute Filter

Answer: B,C

 

NEW QUESTION 121
What is a valid guest portal type?

  • A. Sponsor
  • B. Sponsored-Guest
  • C. My Devices
  • D. Captive-Guest

Answer: B

Explanation:
Section: Web Auth and Guest Services
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/ b_ise_admin_guide_sample_chapter_01111.html

 

NEW QUESTION 122
A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

  • A. NoCoA
  • B. Port Bounce
  • C. Reauth
  • D. Disconnect

Answer: A

Explanation:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design

 

NEW QUESTION 123
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)

  • A. IOS
  • B. Shell
  • C. ASA
  • D. Firepower
  • E. WLC

Answer: B,E

Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide TACACS+ ProfileTACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets.
The TACACS+ profile definitions are split into two components:
* Common tasks
* Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)-Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
* Shell
* WLC
* Nexus
* Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.

 

NEW QUESTION 124
What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?

  • A. Cisco-av-pair
  • B. State attribute
  • C. Event
  • D. Class attribute

Answer: A

Explanation:
Section: Profiler
Explanation/Reference: https://community.cisco.com/t5/network-access-control/ise-airespace-acl-wlc-problem/td- p/2110491

 

NEW QUESTION 125
What are two benefits of TACACS+ versus RADIUS for device administration? (Choose two )

  • A. TACACS+ encrypts the whole payload, and RADIUS encrypts only the password.
  • B. TACACS+ supports 802.1X, and RADIUS supports MAB
  • C. TACACS+ uses UDP, and RADIUS uses TCP
  • D. TACACS+ provides the service type, and RADIUS does not
  • E. TACACS+ has command authorization, and RADIUS does not.

Answer: A,E

 

NEW QUESTION 126
An engineer is implementing Cisco ISE and needs to configure 802.1X. The port settings are configured for port-based authentication. Which command should be used to complete this configuration?

  • A. authentication port-control auto
  • B. aaa authentication dot1x default group radius
  • C. dot1x pae authenticator
  • D. dot1x system-auth-control

Answer: D

Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sg/configuration/guide/conf/dot1x.

 

NEW QUESTION 127
What are the three default behaviors of Cisco ISE with respect to authentication, when a user connects to a switch that is configured for 802.1X, MAB, and WebAuth? (Choose three)

  • A. Dot1X traffic uses a user-defined identity store for retrieving identity.
  • B. Unmatched traffic is allowed on the network.
  • C. Unmatched traffic is dropped because of the Reject/Reject/Drop action that is configured under Options.
  • D. Dot1x traffic uses internal users for retrieving identity.
  • E. MAB traffic uses internal endpoints for retrieving identity.

Answer: A,C,E

 

NEW QUESTION 128
Refer to the exhibit.

A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server Which two commands should be run to complete the configuration? (Choose two)

  • A. aaa authorization auth-proxy default group radius
  • B. ip device tracking
  • C. dot1x system-auth-control
  • D. radius server vsa sand authentication
  • E. radius-server attribute 8 include-in-access-req

Answer: D,E

 

NEW QUESTION 129
Which statement is not correct about the Cisco ISE Monitoring node?

  • A. The local collector agent collects logs locally from itself and from any NAD that is configured to send logs to the Policy Service node.
  • B. Cisco ISE supports distributed log collection across all nodes to optimize local data collection, aggregation, and centralized correlation and storage.
  • C. The local collector buffers transport the collected data to designated Cisco ISE Monitoring nodes as syslog; once Monitoring nodes are globally defined via Administration, ISE nodes automatically send logs to one or both of the configured Monitoring nodes.
  • D. The local collector agent process runs only the Inline Posture node.

Answer: D

 

NEW QUESTION 130

Refer to the exhibit. In which scenario does this switch configuration apply?

  • A. when preventing users with hypervisor
  • B. when passing IP phone authentication
  • C. when allowing a hub with multiple clients connected
  • D. when allowing multiple IP phones to be connected

Answer: C

Explanation:
Explanation
https://www.linkedin.com/pulse/mac-authentication-bypass-priyanka-kumari#:~:text=Multi%2Dauthentication%

 

NEW QUESTION 131
Refer to the exhibit:

Which command is typed within the CLI of a switch to view the troubleshooting output?

  • A. show authentication interface gigabitethemet2/0/36
  • B. show authentication registrations
  • C. show authentication sessions mac 000e.84af.59af details
  • D. show authentication sessions method

Answer: C

 

NEW QUESTION 132
What is the condition that a Cisco ISE authorization policy cannot match?

  • A. time
  • B. custom
  • C. device type
  • D. company contact
  • E. posture

Answer: D

 

NEW QUESTION 133
An organization wants to standardize the 802 1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide What must be configured to accomplish this task?

  • A. extended access-list on the switch for the client
  • B. port security on the switch based on the client's information
  • C. security group tag within the authorization policy
  • D. dynamic access list within the authorization profile

Answer: C

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_sga_pol.html#

 

NEW QUESTION 134
What is a function of client provisioning?

  • A. Client provisioning ensures that endpoints receive the appropriate posture agents.
  • B. Client provisioning checks a dictionary attribute with a value.
  • C. Client provisioning ensures an application process is running on the endpoint.
  • D. Client provisioning checks the existence, date, and versions of the file on a client.

Answer: A

Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_client_prov.html#:~:text=After%20C

 

NEW QUESTION 135
A network engineer is configuring a network device that needs to filter traffic based on security group tags using a security policy on a routed interface.
Which command should be used to accomplish this task?

  • A. cts role-based enforcement
  • B. cts cache enable
  • C. cts role-based policy priority-static
  • D. cts authorization list

Answer: A

Explanation:
Section: Architecture and Deployment

 

NEW QUESTION 136
......

Latest 2022 Realistic Verified 300-715 Dumps - 100% Free 300-715 Exam Dumps: https://www.real4prep.com/300-715-exam.html

Get 2022 Updated Free Cisco 300-715 Exam Questions and Answer: https://drive.google.com/open?id=1Vh-3Y3v2dU0BAZzgYfPAZ-0e2HN2wViD