
[Dec-2021] 300-715 Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund
Pass Cisco 300-715 Exam With Practice Test Questions Dumps Bundle
Exam Topics
The Cisco 300-715 exam measures the applicants’ expertise related to a variety of knowledge areas. The skills measured within this certification test can be grouped into seven domains that are outlined below:
- Architecture & Deployment – 10%
This topic checks the expertise of the examinees in configuring personas as well as describing deployment options.
- Policy Enforcement – 25%
Within this domain, the test takers are required to demonstrate that they are capable of configuring native LDAP and AD; describing identity store options (including LDAP, AD, PKI, OTP, Smart Card, and Local); configuring wired/wireless 802.1X network access. Besides that, the students should be conversant with configuring 802.1X phasing deployment (including monitor mode, closed mode, low impact); configuring network access devices; applying MAB; configuring Cisco TrustSec; configuring policies such as authorization and authentication profiles.
- Web Auth and Guest Services – 15%
To answer the questions from this subject area, the applicants need to have the ability to customize web authentication, customize guest access services as well as customize guest and sponsor portals.
- Profiler – 15%
This section encompasses such skills as implementing profiler services; implementing probes; implementing CoA; configuring endpoint identity management.
- BYOD – 15%
Here the learners must prove that they possess competency in describing Cisco BYOD functionality (including solution components, utilization cases & requirements, as well as BYOD flow); customizing BYOD device on-boarding with the help of internal CA with Cisco wireless LAN controllers as well as Cisco switches; configuring certificates for BYOD; configuring allow list/block list.
- Endpoint Compliance – 10%
This objective requires that the candidates have an understanding of describing posture services, endpoint compliance, as well as client provisioning. They should also be conversant with configuring posture policy, conditions, client provisioning; configuring the compliance module; configuring Cisco ISE posture agents as well as operational modes; describing supplicant, authenticator, server, and supplicant options.
- Network Access Device Administration – 10%
This last part of the certification test comprises of such abilities as comparing AAA protocols and configuring TACACS+ device administration & command authorization.
The percentages provided next to the domains’ titles indicate the share of the questions in the exam content. During your preparation for the test, you need to pay special attention to the topics with higher weights. However, only the mastery of all these objectives guarantees success in Cisco 300-715. Note that the above-mentioned sections are just the provisionary guidelines for the candidates and other subject areas can be included in the specific delivery of the exam without any notice.
NEW QUESTION 67
The default Cisco ISE node configuration has which role or roles enabled by default?
- A. Administration and Pokey Service
- B. Administration only
- C. Inline Posture only
- D. Policy Service Monitoring, and Administration
Answer: D
NEW QUESTION 68
An engineer is configuring web authentication and needs to allow specific protocols to permit DNS traffic.
Which type of access list should be used for this configuration?
- A. extended ACL
- B. reflexive ACL
- C. standard ACL
- D. numbered ACL
Answer: A
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION 69
An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node.
Which persona should be configured with the largest amount of storage in this environment?
- A. Primary Administration
- B. Platform Exchange Grid
- C. policy Services
- D. Monitoring and Troubleshooting
Answer: D
NEW QUESTION 70
An administrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs. Besides defining a new shell profile in Cisco ISE. what must be done to accomplish this configuration?
- A. Enable the privilege levels in Cisco ISE
- B. Enable the privilege levels in the IOS devices.
- C. Define the command privileges for levels 2-5 in the IOS devices
- D. Define the command privileges for levels 2-5 in Cisco ISE
Answer: C
NEW QUESTION 71
A policy is being created in order to provide device administration access to the switches on a network. There is a requirement to ensure that if the session is not actively being used, after 10 minutes, it will be disconnected. Which task must be configured in order to meet this requirement?
- A. idle time
- B. set attribute as
- C. session timeout
- D. monitor
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_admin_acc
NEW QUESTION 72
Which two ports do network devices typically use for CoA? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
Answer: A,E
Explanation:
Section: Profiler
Explanation/Reference: https://documentation.meraki.com/MR/Encryption_and_Authentication/ Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points
NEW QUESTION 73
An administrator is configuring a Cisco ISE posture agent in the client provisioning policy and needs to ensure that the posture policies that interact with clients are monitored, and end users are required to comply with network usage rules Which two resources must be added in Cisco ISE to accomplish this goal? (Choose two)
- A. AnyConnect
- B. Posture Agent
- C. Cisco ISE NAC
- D. PEAP
- E. Supplicant
Answer: A,B
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_An
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_configure_clien
NEW QUESTION 74
Which personas can a Cisco ISE node assume'?
- A. policy service, gatekeeping, and monitoring
- B. administration, policy service, and monitoring
- C. administration, policy service, gatekeeping
- D. administration, monitoring, and gatekeeping
Answer: B
Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html The persona or personas of a node determine the services provided by a node. An ISE node can assume any or all of the following personas: Administration, Policy Service, and Monitoring. The menu options that are available through the administrative user interface are dependent on the role and personas that an ISE node assumes. See Cisco ISE Nodes and Available Menu Options for more information.
NEW QUESTION 75
What is a method for transporting security group tags throughout the network?
- A. by embedding the security group tag in the 802.1Q header
- B. by enabling 802.1AE on every network device
- C. by embedding the security group tag in the IP header
- D. by the Security Group Tag Exchange Protocol
Answer: D
NEW QUESTION 76
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two )
- A. administration
- B. primary
- C. publisher
- D. policy service
- E. subscriber
Answer: A,D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_010.html
NEW QUESTION 77
An administrator is configuring posture with Cisco ISE and wants to check that specific services are present on the workstations that are attempting to access the network. What must be configured to accomplish this goal?
- A. Create a registry posture condition using a non-OPSWAT API version.
- B. Create a compound posture condition using a OPSWAT API version.
- C. Create an application posture condition using a OPSWAT API version.
- D. Create a service posture condition using a non-OPSWAT API version.
Answer: A
NEW QUESTION 78
A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?
- A. The certificate checks are not being conducted.
- B. The AD join point is no longer connected.
- C. The AD DNS response is slow.
- D. The network devices ports are shut down.
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612
NEW QUESTION 79
What is a requirement for Feed Service to work?
- A. TCP port 3080 must be opened between Cisco ISE and the feed server
- B. Cisco ISE has a base license.
- C. Cisco ISE has Internet access to download feed update
- D. Cisco ISE has access to an internal server to download feed update
Answer: B
NEW QUESTION 80
A company is attempting to improve their BYOD policies and restrict access based on certain criteri a. The company's subnets are organized by building. Which attribute should be used in order to gain access based on location?
- A. static group assignment
- B. IP address
- C. MAC address
- D. device registration status
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html#ID1353
NEW QUESTION 81
Which two probes must be enabled for the ARP cache to function in the Cisco ISE profile service so that a user can reliably bind the IP address and MAC addresses of endpoints? (Choose two.)
- A. SNMP
- B. DHCP
- C. HTTP
- D. RADIUS
- E. NetFlow
Answer: B,D
Explanation:
Cisco ISE implements an ARP cache in the profiling service, so that you can reliably map the IP addresses and the MAC addresses of endpoints. For the ARP cache to function, you must enable either the DHCP probe or the RADIUS probe. The DHCP and RADIUS probes carry the IP addresses and the MAC addresses of endpoints in the payload data. The dhcp-requested address attribute in the DHCP probe and the Framed-IP-address attribute in the RADIUS probe carry the IP addresses of endpoints, along with their MAC addresses, which can be mapped and stored in the ARP cache.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html
NEW QUESTION 82
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
- A. endpoint
- B. unknown
- C. allow list
- D. block list
- E. profiled
Answer: B,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group. These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
Workstation-An identity group that contains all the profiled workstations on your network.
NEW QUESTION 83
An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones. The phones do not have the ability to auto switch port for authentication?
- A. enable bypass-MAC
- B. enable network-authentication
- C. dot1x system-auth-control
- D. mab
Answer: D
NEW QUESTION 84
What are the three default behaviors of Cisco ISE with respect to authentication, when a user connects to a switch that is configured for 802.1X, MAB, and WebAuth? (Choose three)
- A. Dot1X traffic uses a user-defined identity store for retrieving identity.
- B. Unmatched traffic is allowed on the network.
- C. MAB traffic uses internal endpoints for retrieving identity.
- D. Unmatched traffic is dropped because of the Reject/Reject/Drop action that is configured under Options.
- E. Dot1 traffic uses internal users for retrieving identity.
Answer: C,D,E
NEW QUESTION 85
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two)
- A. BYOD
- B. hotspot
- C. new AD user 802 1X authentication
- D. guest AUP
Answer: A,C
NEW QUESTION 86
......
2021 Valid 300-715 test answers & Cisco Exam PDF: https://www.exams-boost.com/300-715-valid-materials.html
Free Cisco 300-715 Exam Questions & Answer from Training Expert Exams-boost: https://drive.google.com/open?id=1YZtGKMs682Fip4FH8DTKwy2ZnYo3feGx