[2021] 300-715 All-in-One Exam Guide Practice To your 300-715 Exam!
Preparations of 300-715 Exam 2021 CCNP Security Unlimited 153 Questions
NEW QUESTION 28
An engineer is configuring a dedicated SSID for onboarding devices. Which SSID type accomplishes this configuration?
- A. guest
- B. hidden
- C. broadcast
- D. dual
Answer: A
NEW QUESTION 29
Which command displays all 802 1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?
- A. show authentication sessions interface Gi1/0/x output
- B. Show authentication sessions
- C. show authentication sessions interface Gi 1/0/x
- D. show authentication sessions output
Answer: A
NEW QUESTION 30
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
- A. unknown
- B. profiled
- C. allow list
- D. endpoint
- E. block list
Answer: A,B
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
* Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
* GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
* Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
* RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group.
* These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
* Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
* Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
* Workstation-An identity group that contains all the profiled workstations on your network.
NEW QUESTION 31
Refer to the exhibit Which switch configuration change will allow only one voice and one data endpoint on each port?
- A. Multi-auth to multi-domain
- B. Multi-auth to single-auth
- C. Auto to manual
- D. Mab to dot1x
Answer: A
Explanation:
Reference:
https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907
NEW QUESTION 32
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.
Answer:
Explanation:
NEW QUESTION 33
What is a function of client provisioning?
- A. Client provisioning ensures an application process is running on the endpoint.
- B. Client provisioning checks the existence, date, and versions of the file on a client.
- C. Client provisioning checks a dictionary attribute with a value.
- D. Client provisioning ensures that endpoints receive the appropriate posture agents.
Answer: A
NEW QUESTION 34
A network administrator is configuring a secondary cisco ISE node from the backup configuration of the primary cisco ISE node to create a high availability pair The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE Which command most be issued for this to work?
- A. application configure Ise
- B. certificate configure Ise
- C. Import certificate Ise
- D. copy certificate Ise
Answer: A
Explanation:
https://community.cisco.com/t5/network-access-control/ise-certificate-import-export/m-p/3847746
NEW QUESTION 35
Which supplicant(s) and server(s) are capable of supporting EAP-CHAINING?
- A. Cisco AnyConnect NAM and Cisco Access Control Server
- B. Cisco Secure Services Client and Cisco Access Control Server
- C. Cisco AnyConnect NAM and Cisco Identity Service Engine
- D. Windows Native Supplicant and Cisco Identity Service Engine
Answer: C
NEW QUESTION 36
What gives Cisco ISE an option to scan endpoints for vulnerabilities?
- A. authentication profile
- B. authorization policy
- C. authorization profile
- D. authentication policy
Answer: C
Explanation:
Section: Policy Enforcement
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/ b_ise_admin_guide_22_chapter_010100.html
NEW QUESTION 37
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.
Answer:
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide Step 1 Choose Administration > System > Deployment.
The Register button will be disabled initially. To enable this button, you must configure a Primary PAN.
Step 2
Check the check box next to the current node, and click Edit.
Step 3
Click Make Primary to configure your Primary PAN.
Step 4
Enter data on the General Settings tab.
Step 5
Click Save to save the node configuration.
NEW QUESTION 38
An engineer is configuring a guest password policy and needs to ensure that the password complexity requirements are set to mitigate brute force attacks. Which two requirement complete this policy? (Choose two)
- A. active username limit
- B. gpassword expiration period
- C. username expiration date
- D. access code control
- E. minimum password length
Answer: B,E
NEW QUESTION 39
Which three default endpoint identity groups does cisco ISE create? (Choose three)
- A. profiled
- B. whitelist
- C. blacklist
- D. end point
- E. Unknown
Answer: A,C,E
Explanation:
Default Endpoint Identity Groups Created for Endpoints
Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_010101.html#ID1678
NEW QUESTION 40
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE. The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- B. Confirm the authorization policies are correct using the test aaa authorization admin drop legacy command.
- C. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- D. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
Answer: D
Explanation:
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4b13ab285f51
NEW QUESTION 41
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.
Answer:
Explanation:
NEW QUESTION 42
When planning for the deployment of Cisco ISE, an organization's security policy dictates that they must use network access authentication via RADIUS. It also states that the deployment provide an adequate amount of security and visibility for the hosts on the network. Why should the engineer configure MAB in this situation?
- A. The devices in the network do not have a supplicant.
- B. MAB provides the strongest form of authentication available.
- C. MAB provides user authentication.
- D. The Cisco switches only support MAB.
Answer: A
NEW QUESTION 43
If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?
- A. Guest
- B. Blacklist
- C. Client Provisioning
- D. BYOD
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/ BY OD_Design_Guide/Managing_Lost_or_Stolen_Device.html#90273 The Blacklist identity group is system generated and maintained by ISE to prevent access to lost or stolen devices. In this design guide, two authorization profiles are used to enforce the permissions for wireless and wired devices within the Blacklist:
Blackhole WiFi Access
Blackhole Wired Access
NEW QUESTION 44
An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected.
Which service should be used to accomplish this task?
- A. guest access
- B. client provisioning
- C. profiling
- D. posture
Answer: C
Explanation:
Section: Profiler
Explanation
NEW QUESTION 45
An organization is hosting a conference and must make guest accounts for several of the speakers attending.
The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
- A. Create an authorization rule denying sponsored guest access.
- B. Navigate to the Guest Portal and delete the guest accounts.
- C. Navigate to the Sponsor Portal and suspend the guest accounts.
- D. Create an authorization rule denying guest access.
Answer: D
NEW QUESTION 46
Which are two characteristics of TACACS+? (Choose two ) ,
- A. It combines authorization and authentication functions.
- B. It separates authorization and authentication functions.
- C. It uses TCP port 49.
- D. It encrypts the password only.
- E. It uses UDP port 49.
Answer: A,D
NEW QUESTION 47
When setting up profiling in an environment using Cisco ISE for network access control, an organization must use non-proprietary protocols for collecting the information at layer 2. Which two probes will provide this information without forwarding SPAN packets to Cisco ISE? {Choose two.)
- A. RADIUS probe
- B. NetFlow probe
- C. SNMP query probe
- D. DHCP SPAN probe
- E. DNS probe
Answer: A,C
NEW QUESTION 48
In a Cisco ISE split deployment model, which load is split between the nodes?
- A. AAA
- B. device admission
- C. network admission
- D. log collection
Answer: D
Explanation:
Section: Architecture and Deployment
NEW QUESTION 49
An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?
- A. RADIUS probe
- B. HTTP probe
- C. NetFlow probe
- D. network scan probe
Answer: B
NEW QUESTION 50
......
Focus on 300-715 All-in-One Exam Guide For Quick Preparation: https://www.exams-boost.com/300-715-valid-materials.html
Practice To 300-715 - Exams-boost Remarkable Practice On your Implementing and Configuring Cisco Identity Services Engine Exam: https://drive.google.com/open?id=1EAJOMddxR6n4aLzLXu2fyOAKByP7k1g0