[Apr-2023] Cisco 300-715 Exam Basic Questions With Answers [Q43-Q68]

Share

[Apr-2023] Cisco 300-715 Exam: Basic Questions With Answers

New 2023 Realistic Free Cisco 300-715 Exam Dump Questions and Answer


The Cisco 300-715 certification exam is designed for IT professionals who plan, design, implement, operate, and troubleshoot complex Security technologies and solutions. The exam measures the candidate’s knowledge in implementing and configuring Cisco Identity Services Engine (ISE) solutions. The Cisco ISE is a security policy management platform that provides comprehensive visibility and control over users and devices accessing network resources.

 

NEW QUESTION # 43
What is a characteristic of the UDP protocol?

  • A. UDP offers information about a non-existent server
  • B. UDP offers best-effort delivery
  • C. UDP can detect when a server is slow
  • D. UDP can detect when a server is down.

Answer: B

Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-1


NEW QUESTION # 44
Which two components are required for creating a Native Supplicant Profile within a BYOD flow?
(Choose two )

  • A. iOS Settings
  • B. Redirect ACL Operating System
  • C. Connection Type
  • D. Windows Settings

Answer: A,D


NEW QUESTION # 45
Refer to the exhibit:

Which command is typed within the CU of a switch to view the troubleshooting output?

  • A. show authentication sessions mac 000e.84af.59af details
  • B. show authentication registrations
  • C. show authentication sessions method
  • D. show authentication interface gigabitethemet2/0/36

Answer: A


NEW QUESTION # 46
Drag the descriptions on the left onto the components of 802.1X on the right.

Answer:

Explanation:


NEW QUESTION # 47
An employee logs on to the My Devices portal and marks a currently on-boarded device as 'Lost'.
Which two actions occur within Cisco ISE as a result oí this action? (Choose two)

  • A. Certificates provisioned to the device are not revoked
  • B. The device status is updated to Stolen
  • C. BYOD Registration status is updated to Unknown.
  • D. The device access has been denied
  • E. BYOD Registration status is updated to No

Answer: A,E

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html


NEW QUESTION # 48
What must be configured on the Cisco ISE authentication policy for unknown MAC addresses/identities for successful authentication?

  • A. reject
  • B. continue
  • C. pass
  • D. drop

Answer: B

Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html


NEW QUESTION # 49
An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as "Medical Switch" so that the policies can be made separately for the endpoints connecting through them. Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal?

  • A. Change the device location to Medical Switch.
  • B. Change the device profile to Medical Switch.
  • C. Change the device type to Medical Switch.
  • D. Change the model name to Medical Switch.

Answer: C


NEW QUESTION # 50
What should be considered when configuring certificates for BYOD?

  • A. The CN field is populated with the endpoint host name.
  • B. The SAN field is populated with the end user name
  • C. An Android endpoint uses EST whereas other operation systems use SCEP for enrollment
  • D. An endpoint certificate is mandatory for the Cisco ISE BYOD

Answer: D


NEW QUESTION # 51
A network engineer is configuring Cisco TrustSec and needs to ensure that the Security Group Tag is being transmitted between two devices Where in the Layer 2 frame should this be verified?

  • A. 802.1Q filed
  • B. 802.1 AE header
  • C. Payload
  • D. CMD filed

Answer: D

Explanation:
https://www.cisco.com/c/dam/global/en_ca/assets/ciscoconnect/2014/pdfs/policy_defined_segmentation_with_trustsec_rob_bleeker.pdf (slide 25)


NEW QUESTION # 52
An engineer needs to configure a new certificate template in the Cisco ISE Internal Certificate Authority to prevent BYOD devices from needing to re-enroll when their MAC address changes. Which option must be selected in the Subject Alternative Name field?

  • A. Common Name and GUID
  • B. MAC Address and GUID
  • C. Common Name
  • D. Distinguished Name

Answer: B

Explanation:
The engineer needs to select the option of MAC Address and GUID in the Subject Alternative Name field when configuring a new certificate template in the Cisco ISE Internal Certificate Authority to prevent BYOD devices from needing to re-enroll when their MAC address changes.


NEW QUESTION # 53
Refer to the exhibit. Which command is typed within the CU of a switch to view the troubleshooting output?

  • A. show authentication sessions mac 000e.84af.59af details
  • B. show authentication registrations
  • C. show authentication sessions method
  • D. show authentication interface gigabitethemet2/0/36

Answer: A


NEW QUESTION # 54
Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE? (Choose two).

  • A. TCP 8905
  • B. TCP 8443
  • C. TCP 8906
  • D. DTCP80
  • E. TCP 443

Answer: A,D


NEW QUESTION # 55
An adminístrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs. Besides defining a new shell profile in Cisco ISE. what must be done to accomplish this configuration?

  • A. Enable the privilege levels in the IOS devices.
  • B. Enable the privilege levels in Cisco ISE
  • C. Define the command privileges for levels 2-5 in the IOS devices
  • D. Define the command privileges for levels 2-5 in Cisco ISE

Answer: A

Explanation:
https://learningnetwork.cisco.com/s/blogs/a0D3i000002eeWTEAY/cisco-ios-privilege-levels


NEW QUESTION # 56
An administrator is configuring posture assessment in Cisco ISE for the first time. Which two components must be uploaded to Cisco ISE to use Anyconnect for the agent configuration in a client provisioning policy? (Choose two.)

  • A. AnyConnectProfile.xsd file
  • B. Anyconnect agent image
  • C. Anyconnect compliance module
  • D. AnyConnectProfile.xml file
  • E. Anyconnect network visibility module

Answer: A,C


NEW QUESTION # 57
Which two default endpoint identity groups does Cisco ISE create? (Choose two )

  • A. unknown
  • B. block list
  • C. profiled
  • D. endpoint
  • E. allow list

Answer: A,C

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group. These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
Workstation-An identity group that contains all the profiled workstations on your network.


NEW QUESTION # 58
Which two features must be used on Cisco ISE to enable the TACACS+ feature? (Choose two.)

  • A. Device Admin Service
  • B. Command Sets
  • C. Server Sequence
  • D. External TACACS Servers
  • E. Device Administration License

Answer: A,E

Explanation:
Section: Network Access Device Administration
Explanation/Reference:


NEW QUESTION # 59
An administrator is trying to collect metadata information about the traffic going across the network to gam added visibility into the hosts. This Information will be used to create profiling policies for devices us mg Cisco ISE so that network access policies can be used What must be done to accomplish this task?

  • A. Configure SNMP to be used with the Cisco ISE appliance
  • B. Configure NetFlow to be sent to me Cisco ISE appliance.
  • C. Configure the RADIUS profiling probe within Cisco ISE
  • D. Configure the DHCP probe within Cisco ISE

Answer: B


NEW QUESTION # 60
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

  • A. BYOD
  • B. Guest
  • C. Blacklist
  • D. Client Provisioning

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/Managing_Lost_or_Stolen_Device.html#90273 The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
Blackhole WiFi Access
Blackhole Wired Access


NEW QUESTION # 61
An engineer is migrating users from MAB to 802.1X on the network. This must be done during normal business hours with minimal impact to users. Which CoA method should be used?

  • A. Port Bounce
  • B. Session Reauthentication
  • C. Session Termination
  • D. Port Shutdown

Answer: B


NEW QUESTION # 62
Refer to the exhibit Which component must be configured to apply the SGACL?

  • A. ingress router
  • B. host
  • C. egress router
  • D. secure server

Answer: C

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/arch_over.html#52796


NEW QUESTION # 63
What is a restriction of a standalone Cisco ISE node deployment?

  • A. Only the Policy Service persona can be disabled on the node.
  • B. The hostname of the node cannot be changed after installation.
  • C. Personas are enabled by default and cannot be edited on the node.
  • D. The domain name of the node cannot be changed after installation.

Answer: C


NEW QUESTION # 64
An administrator is configuring cisco ISE lo authenticate users logging into network devices using TACACS+ The administrator is not seeing any or the authentication in the TACACS+ live logs. Which action ensures the users are able to log into the network devices?

  • A. Enable the device administration service in the Administration persona
  • B. Enable the session services in the administration persona
  • C. Enable the service sessions in the PSN persona.
  • D. Enable the device administration service in the PSN persona.

Answer: A

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html


NEW QUESTION # 65
What happens when an internal user is configured with an external identity store for authentication, but an engineer uses the Cisco ISE admin portal to select an internal identity store as the identity source?

  • A. Authentication fails.
  • B. Authentication is redirected to the internal identity source.
  • C. Authentication is redirected to the external identity source.
  • D. Authentication is granted.

Answer: D


NEW QUESTION # 66
What does the dot1x system-auth-control command do?

  • A. enables 802.1x on a network access device interface
  • B. globally enables 802.1x
  • C. causes a network access switch to track 802.1x sessions
  • D. causes a network access switch not to track 802.1x sessions

Answer: B

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-
24E/configuration/guide/xe-380-configuration/dot1x.html


NEW QUESTION # 67
What is an advantage of using EAP-TLS over EAP-MS-CHAPv2 for client authentication?

  • A. EAP-TLS uses a username and password for authentication to enhance security, while EAP-MS-CHAPv2 does not.
  • B. EAP-TLS uses multiple forms of authentication, while EAP-MS-CHAPv2 only uses one.
  • C. EAP-TLS secures the exchange of credentials, while EAP-MS-CHAPv2 does not.
  • D. EAP-TLS uses a device certificate for authentication to enhance security, while EAP-MS-CHAPv2 does not.

Answer: D


NEW QUESTION # 68
......

Guaranteed Success in CCNP Security 300-715 Exam Dumps: https://itexams.lead2passed.com/Cisco/300-715-practice-exam-dumps.html