Pass Cisco 300-715 Exam in First Attempt Guaranteed [Nov-2024]
Exam Sure Pass Cisco Certification with 300-715 exam questions
NEW QUESTION # 186
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
- A. block list
- B. allow list
- C. unknown
- D. endpoint
- E. profiled
Answer: C,E
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
* Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
* GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
* Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
* RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group.
These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are
* assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
* Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
* Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
* Workstation-An identity group that contains all the profiled workstations on your network.
NEW QUESTION # 187
Refer to the exhibit.
A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server Which two commands should be run to complete the configuration? (Choose two)
- A. radius-server attribute 8 include-in-access-req
- B. aaa authorization auth-proxy default group radius
- C. dot1x system-auth-control
- D. radius server vsa sand authentication
- E. ip device tracking
Answer: A,D
NEW QUESTION # 188
An engineer is configuring 802.1X and wants it to be transparent from the users' point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices. Which deployment mode should be used to achieve this?
- A. closed
- B. open
- C. low-impact
- D. high-impact
Answer: C
Explanation:
Explanation
https://www.lookingpoint.com/blog/cisco-ise-wired-802.1x-deployment-monitormode#:~:text=Low%20imp
NEW QUESTION # 189
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?
- A. BYOD
- B. Client Provisioning
- C. Guest
- D. Blacklist
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/ BY OD_Design_Guide/Managing_Lost_or_Stolen_Device.html#90273 The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
Blackhole WiFi Access
Blackhole Wired Access
NEW QUESTION # 190
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two)
- A. guest AUP
- B. BYOD
- C. hotspot
- D. new AD user 802.1X authentication
- E. posture
Answer: D,E
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-
4/admin_guide/b_ISE_admin_guide_24/m_setup_cisco_ise.html#ID57
The following table lists the features that are affected when the primary PAN goes down and the secondary PAN is yet to take over.
Features Name Available When Primary PAN is Down? (Yes/No)
Existing or new AD user RADIUS authentication Yes
Guest: AUP No
Posture Yes
BYOD with Internal CA No
NEW QUESTION # 191
Which two components are required for creating a Native Supplicant Profile within a BYOD flow?
(Choose two)
- A. Windows Settings
- B. Connection Type
- C. Operating System
- D. iOS Settings
- E. Redirect ACL
Answer: B,C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-
1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01111.html
NEW QUESTION # 192
Which three conditions can be used for posture checking? (Choose three.)
- A. operating system
- B. application
- C. services
- D. file
- E. certificate
Answer: B,C,D
NEW QUESTION # 193
An employee logs on to the My Devices portal and marks a currently on-boarded device as 'Lost'.
Which two actions occur within Cisco ISE as a result of this action? (Choose two)
- A. Certificates provisioned to the device are not revoked
- B. BYOD Registration status is updated to Unknown.
- C. BYOD Registration status is updated to No
- D. The device status is updated to Stolen
- E. The device access has been denied
Answer: A,C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html
NEW QUESTION # 194
An administrator is configuring a Cisco ISE posture agent in the client provisioning policy and needs to ensure that the posture policies that interact with clients are monitored, and end users are required to comply with network usage rules Which two resources must be added in Cisco ISE to accomplish this goal? (Choose two)
- A. PEAP
- B. Supplicant
- C. AnyConnect
- D. Cisco ISE NAC
- E. Posture Agent
Answer: C,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/configure-posture.html
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_configure_client_provisioning.html#task_D1C2E8ECE1D54D259C01BCBF0A5822F1
NEW QUESTION # 195
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)
- A. WLC
- B. IOS
- C. Firepower
- D. ASA
- E. Shell
Answer: A,E
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_0100010.html TACACS+ Profile TACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets. The TACACS+ profile definitions are split into two components:
Common tasks
Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)-Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
Shell
WLC
Nexus
Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.
NEW QUESTION # 196
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
NEW QUESTION # 197
What are two components of the posture requirement when configuring Cisco ISE posture? (Choose two)
- A. access policy
- B. remediation actions
- C. Client Provisioning portal
- D. conditions
- E. updates
Answer: B,D
NEW QUESTION # 198
A network administrator is configuring a secondary cisco ISE node from the backup configuration of the primary cisco ISE node to create a high availability pair The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE Which command most be issued for this to work?
- A. certificate configure Ise
- B. copy certificate Ise
- C. application configure Ise
- D. Import certificate Ise
Answer: C
Explanation:
https://community.cisco.com/t5/network-access-control/ise-certificate-import-export/m-p/3847746
NEW QUESTION # 199
When setting up profiling in an environment using Cisco ISE for network access control, an organization must use non-proprietary protocols for collecting the information at layer 2. Which two probes will provide this information without forwarding SPAN packets to Cisco ISE? {Choose two.)
- A. DHCP SPAN probe
- B. DNS probe
- C. RADIUS probe
- D. SNMP query probe
- E. NetFlow probe
Answer: C,D
Explanation:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design
NEW QUESTION # 200
An engineer is designing a new distributed deployment for Cisco ISE in the network and is considering failover options for the admin nodes. There is a need to ensure that an admin node is available for configuration of policies at all times. What is the requirement to enable this feature?
- A. one policy services node and one secondary admin node
- B. one primary admin node and one monitoring and troubleshooting node
- C. one policy services node and one monitoring and troubleshooting node
- D. one primary admin and one secondary admin node in the deployment
Answer: D
NEW QUESTION # 201
An administrator is configuring sponsored guest access using Cisco ISE Access must be restricted to the sponsor portal to ensure that only necessary employees can issue sponsored accounts and employees must be classified to do so What must be done to accomplish this task?
- A. Create an authorization rule using the Guest Flow condition to authorize the administrators
- B. Modify the sponsor groups assigned to reflect the desired user groups
- C. Edit the sponsor portal to only accept members from the selected groups
- D. Configure an identity-based access list in Cisco ISE to restrict the users allowed to login
Answer: B
NEW QUESTION # 202
There are several devices on a network that are considered critical and need to be placed into the ISE database and a policy used for them. The organization does not want to use profiling. What must be done to accomplish this goal?
- A. Enter the IP address in the correct Endpoint Identity Group.
- B. Enter the MAC address in the correct Endpoint Identity Group.
- C. Enter the MAC address in the correct Logical Profile.
- D. Enter the IP address in the correct Logical Profile.
Answer: A
NEW QUESTION # 203
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
NEW QUESTION # 204
......
Real Cisco 300-715 Exam Questions Study Guide: https://www.real4prep.com/300-715-exam.html
Download Real 300-715 Exam Dumps for candidates. 100% Free Dump Files: https://drive.google.com/open?id=1PtVGpW45xOscV-9et9xsITwUfiF4WM7j