Released Cisco 300-715 Updated Questions PDF
300-715 Dumps and Practice Test (246 Exam Questions)
NEW QUESTION # 81
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.
Answer:
Explanation:
NEW QUESTION # 82
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.
Answer:
Explanation:
Explanation
Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services.
This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide
NEW QUESTION # 83
Select and Place
Answer:
Explanation:
NEW QUESTION # 84
By default, which traffic does an 802.IX-enabled switch allow before authentication?
- A. traffic permitted in the default ACL on the switch
- B. traffic permitted in the port dACL on Cisco ISE
- C. no traffic
- D. all traffic
Answer: C
NEW QUESTION # 85
What is the purpose of the ip http server command on a switch?
- A. It enables MAB authentication on the switch.
- B. It enables the switch to redirect users for web authentication.
- C. It enables dot1x authentication on the switch.
- D. It enables the https server for users for web authentication.
Answer: A
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION # 86
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011.html Step 1 Choose Administration > System > Deployment.
The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click Edit.
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings tab.
Step 5
Click Save to save the node configuration.
NEW QUESTION # 87
Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue. Which two requirements must be met to implement this change? (Choose two.)
- A. Establish access to one Global Catalog server.
- B. Provide domain administrator access to Active Directory.
- C. Enable IPC access over port 80.
- D. Configure a secure LDAP connection.
- E. Ensure that the NAT address is properly configured
Answer: A,B
NEW QUESTION # 88
In a Cisco ISE split deployment model, which load is split between the nodes?
- A. network admission
- B. device admission
- C. log collection
- D. AAA
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/install_guide/b_ise_InstallationGuide26.pdf
NEW QUESTION # 89
What is a requirement for Feed Service to work?
- A. Cisco ISE has Internet access to download feed update
- B. TCP port 3080 must be opened between Cisco ISE and the feed server
- C. Cisco ISE has a base license.
- D. Cisco ISE has access to an internal server to download feed update
Answer: C
NEW QUESTION # 90
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this What should be done to enable this type of posture check?
- A. Use the file registry condition to ensure that the firewal is installed and running appropriately.
- B. Enable the default firewall condition to check for any vendor firewall application.
- C. Enable the default application condition to identify the applications installed and validade the firewall app.
- D. Use a compound condition to look for the Windows or Mac native firewall applications.
Answer: B
Explanation:
https://www.youtube.com/watch?v=6Kj8P8Hn7dY&t=109s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION # 91
Which permission is common to the Active Directory Join and Leave operations?
- A. Set attributes on the Cisco ISE machine account
- B. Create a Cisco ISE machine account in the domain if the machine account does not already exist
- C. Remove the Cisco ISE machine account from the domain.
- D. Search Active Directory to see if a Cisco ISE machine account already ex.sts.
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html
NEW QUESTION # 92
An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+ However, the administrator must restrict certain commands based on one of three user roles that require different commands How is this accomplished without creating too many objects using Cisco ISE?
- A. Create multiple shell profiles and multiple command sets.
- B. Create one shell profile and one command set.
- C. Create one shell profile and multiple command sets.
- D. Create multiple shell profiles and one command set
Answer: A
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_0100010.html
https://www.youtube.com/watch?v=IlZwB71Szog&ab_channel=JasonMaynard
NEW QUESTION # 93
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE.
The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Conrm the authorization policies are correct using the test aaa authorization admin drop legacy command.
- B. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- C. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- D. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
Answer: D
Explanation:
Explanation
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4
NEW QUESTION # 94
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two)
- A. new AD user 802 1X authentication
- B. BYOD
- C. guest AUP
- D. hotspot
Answer: A,B
NEW QUESTION # 95
An organization is hosting a conference and must make guest accounts for several of the speakers attending.
The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
- A. Create an authorization rule denying guest access.
- B. Navigate to the Guest Portal and delete the guest accounts.
- C. Navigate to the Sponsor Portal and suspend the guest accounts.
- D. Create an authorization rule denying sponsored guest access.
Answer: C
NEW QUESTION # 96
Which personas can a Cisco ISE node assume'?
- A. administration, monitoring, and gatekeeping
- B. policy service, gatekeeping, and monitoring
- C. administration, policy service, gatekeeping
- D. administration, policy service, and monitoring
Answer: D
Explanation:
Reference:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html The persona or personas of a node determine the services provided by a node. An ISE node can assume any or all of the following personas: Administration, Policy Service, and Monitoring. The menu options that are available through the administrative user interface are dependent on the role and personas that an ISE node assumes. See Cisco ISE Nodes and Available Menu Options for more information.
NEW QUESTION # 97
An engineer is configuring 802.1X and wants it to be transparent from the users' point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices. Which deployment mode should be used to achieve this?
- A. low-impact
- B. closed
- C. high-impact
- D. open
Answer: A
Explanation:
https://www.lookingpoint.com/blog/cisco-ise-wired-802.1x-deployment-monitormode#:~:text=Low%20impact%20mode%20works%20similar,DHCP%2C%20PXE%20boot%2C%20etc.
NEW QUESTION # 98
An engineer builds a five-node distributed Cisco ISE deployment The first two deployed nodes are responsible for the primary and secondary administration and monitoring personas Which persona configuration is necessary to have the remaining three Cisco ISE nodes serve as dedicated nodes in the Cisco ISE cube that is responsible only for handling the RADIUS and TACACS+ authentication requests, identity lookups, and policy evaluation?
A)
B)
C)
D)
- A. Option C
- B. Option D
- C. Option B
- D. Option A
Answer: B
NEW QUESTION # 99
......
300-715 Exam Dumps Pass with Updated 2024 Certified Exam Questions: https://itexams.lead2passed.com/Cisco/300-715-practice-exam-dumps.html