Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) Question and Answers

Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE)

Last Update Jul 27, 2026
Total Questions : 322

We are offering FREE 300-715 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 300-715 free exam questions and then go for complete pool of Implementing and Configuring Cisco Identity Services Engine (SISE) v1.1 (300-715 SISE) test questions that will help you more.

300-715 pdf

300-715 PDF

$40.25  $114.99
300-715 Engine

300-715 Testing Engine

$47.25  $134.99
300-715 PDF + Engine

300-715 PDF + Testing Engine

$61.25  $174.99
Questions 1

An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not hitting the correct policies. This was working correctly on the previous PSN. Which action must be taken to ensure the endpoints get identified?

Options:

A.  

Verify that the MnT node is tracking the session.

B.  

Verify the shared secret used between the switch and the PSN.

C.  

Verify that the profiling service is running on the new PSN.

D.  

Verify that the authentication request the PSN is receiving is not malformed.

Discussion 0
Questions 2

Which permission is common to the Active Directory Join and Leave operations?

Options:

A.  

Create a Cisco ISE machine account in the domain if the machine account does not already exist

B.  

Remove the Cisco ISE machine account from the domain.

C.  

Set attributes on the Cisco ISE machine account

D.  

Search Active Directory to see if a Cisco ISE machine account already ex.sts.

Discussion 0
Questions 3

ESTION NO: 100

An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE. What must be configured within Cisco ISE to accomplish this goal?

Options:

A.  

Create a certificate signing request and have the root certificate authority sign it.

B.  

Add the root certificate authority to the trust store and enable it for authentication.

C.  

Create an SCEP profile to link Cisco ISE with the root certificate authority.

D.  

Add an OCSP profile and configure the root certificate authority as secondary.

Discussion 0
Questions 4

An administrator must configure Cisco ISE to authenticate a user accessing a Cisco Adaptive Security Appliance firewall through SSH. The solution must meet these requirements:

• The local Cisco ISE database must be used for user authentication.

• ASA commands run by users must be validated.

These configurations were performed:

• Added the Cisco Adaptive Security Appliance firewall

• Configured user accounts

• Enabled the Device Admin service in Cisco ISE

• Configured a TACACS+ profile

• Configured an authorization policy

• Configured the ASA firewall for authentication and authorization

Which two actions must be taken in Cisco ISE? (Choose two.)

Options:

A.  

Configure an authentication profile.

B.  

Enable local authentication.

C.  

Configure an authorization profile.

D.  

Configure TACACS+ command sets.

E.  

Configure a user identity group.

Discussion 0
Questions 5

An engineer is configuring a posture policy for Windows 10 endpoints and wants to ensure that users in each AD group have different conditions to meet to be compliant. What must be done to accomplish this task?

Options:

A.  

identify The users groups needed for different policies and create service conditions to map each one to its posture requirement

B.  

Configure a simple condition for each AD group and use it in the posture policy for each use case

C.  

Use the authorization policy within the policy set to group each AD group with their respective posture policy

D.  

Change the posture requirements to use an AD group lor each use case then use those requirements in the posture policy

Discussion 0
Questions 6

What is needed to configure wireless guest access on the network?

Options:

A.  

endpoint already profiled in ISE

B.  

WEBAUTH ACL for redirection

C.  

valid user account in Active Directory

D.  

Captive Portal Bypass turned on

Discussion 0
Questions 7

Refer to the exhibit Which component must be configured to apply the SGACL?

Options:

A.  

egress router

B.  

host

C.  

secure server

D.  

ingress router

Discussion 0
Questions 8

What is a valid status of an endpoint attribute during the device registration process?

Options:

A.  

block listed

B.  

pending

C.  

unknown

D.  

DenyAccess

Discussion 0
Questions 9

An administrator is configuring the Native Supplicant Profile to be used with the Cisco ISE posture agents and needs to test the connection using wired devices to determine which profile settings are available. Which two configuration settings should be used to accomplish this task? (Choose two.)

Options:

A.  

authentication mode

B.  

proxy host/IP

C.  

certificate template

D.  

security

E.  

allowed protocol

Discussion 0
Questions 10

Which personas can a Cisco ISE node assume ' ?

Options:

A.  

policy service, gatekeeping, and monitoring

B.  

administration, policy service, and monitoring

C.  

administration, policy service, gatekeeping

D.  

administration, monitoring, and gatekeeping

Discussion 0
Questions 11

An administrator adds a new network device to the Cisco ISE configuration to authenticate endpoints to the network. The RADIUS test fails after the administrator configures all of the settings in Cisco ISE and adds the proper configurations to the switch. What is the issue " ?

Options:

A.  

The endpoint profile is showing as " unknown. "

B.  

The endpoint does not have the appropriate credentials for network access.

C.  

The shared secret is incorrect on the switch or on Cisco ISE.

D.  

The certificate on the switch is self-signed not a CA-provided certificate.

Discussion 0
Questions 12

What is a valid guest portal type?

Options:

A.  

Sponsored-Guest

B.  

My Devices

C.  

Sponsor

D.  

Captive-Guest

Discussion 0
Questions 13

Which Cisco ISE deployment model is recommended for an enterprise that has over 50,000 concurrent active endpoints?

Options:

A.  

large deployment with fully distributed nodes running all personas

B.  

medium deployment with primary and secondary PAN/MnT/pxGrid nodes with shared PSNs

C.  

medium deployment with primary and secondary PAN/MnT/pxGrid nodes with dedicated PSNs

D.  

small deployment with one primary and one secondary node running all personas

Discussion 0
Questions 14

An administrator wants to configure network device administration and is trying to decide whether to use TACACS* or RADIUS. A reliable protocol must be used that can check command authorization Which protocol meets these requirements and why?

Options:

A.  

TACACS+ because it runs over TCP

B.  

RADIUS because it runs over UDP

C.  

RADIUS because it runs over TCP.

D.  

TACACS+ because it runs over UDP

Discussion 0
Questions 15

Refer to the exhibit.

An engineer must configure Cisco ISE to be used as the TACACS+ server for any administrator that signs into the router. Users must be able to change their Telnet password through the TACACS+ server. Drag and drop the configuration steps from the left into the sequence on the right.

Options:

Discussion 0
Questions 16

An engineer wants to learn more about Cisco ISE and deployed a new lab with two nodes. Which two persona configurations allow the engineer to successfully test redundancy of a failed node? (Choose two.)

Options:

A.  

Configure one of the Cisco ISE nodes as the Health Check node.

B.  

Configure both nodes with the PAN and MnT personas only.

C.  

Configure one of the Cisco ISE nodes as the primary PAN and MnT personas and the other as the secondary.

D.  

Configure both nodes with the PAN, MnT, and PSN personas.

E.  

Configure one of the Cisco ISE nodes as the primary PAN and PSN personas and the other as the secondary.

Discussion 0
Questions 17

An administrator has added a new Cisco ISE PSN to their distributed deployment. Which two features must the administrator enable to accept authentication requests and profile the endpoints correctly, and add them to their respective endpoint identity groups? (Choose two )

Options:

A.  

Session Services

B.  

Endpoint Attribute Filter

C.  

Posture Services

D.  

Profiling Services

E.  

Radius Service

Discussion 0
Questions 18

An engineer must create and sign a new certificate for all the portals in a Cisco ISE environment. The company reports that wildcard certificates are blocked in the environment. Which action must the engineer take before signing the certificate?

Options:

A.  

Create a DNS AAAA record for the FQDN of each portal.

B.  

Add the FQDN of each portal to the Common Name field in the certificate signing request.

C.  

Create a DNS AAAA record for the FQDN of the Cisco ISE Administration node.

D.  

Add the FQDN of each portal to the Subject Alternative Name field in the certificate signing request.

Discussion 0
Questions 19

What must match between Cisco ISE and the network access device to successfully authenticate endpoints?

Options:

A.  

SNMP version

B.  

shared secret

C.  

certificate

D.  

profile

Discussion 0
Questions 20

An engineer must deploy a WLAN that supports identity networking. The Cisco Wireless LAN Controller must be configured to apply the VLAN tag for client traffic returned by the RADIUS server. Which configuration parameter on the Cisco Wireless LAN Controller must be enabled to meet the requirement?

Options:

A.  

Change of Authorization

B.  

CWA Redirect ACL

C.  

Allow AAA Override

D.  

FlexConnect

Discussion 0
Questions 21

Which two roles are taken on by the administration person within a Cisco ISE distributed environment? (Choose two.)

Options:

A.  

backup

B.  

secondary

C.  

standby

D.  

primary

E.  

active

Discussion 0
Questions 22

An administrator is configuring a new profiling policy in Cisco ISE for a printer type that is missing from the profiler feed The logical profile Printers must be used in the authorization rule and the rule must be hit. What must be done to ensure that this configuration will be successful^

Options:

A.  

Create a new logical profile for the new printer policy

B.  

Enable the EndPoints:EndPointPolicy condition in the authorization policy.

C.  

Add the new profiling policy to the logical profile Printers.

D.  

Modify the profiler conditions to ensure that it goes into the correct logical profile

Discussion 0
Questions 23

An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?

Options:

A.  

authentication open

B.  

pae dot1x enabled

C.  

authentication host-mode multi-auth

D.  

monitor-mode enabled

Discussion 0
Questions 24

Which two features must be used on Cisco ISE to enable the TACACS. feature? (Choose two)

Options:

A.  

Device Administration License

B.  

Server Sequence

C.  

Command Sets

D.  

Enable Device Admin Service

E.  

External TACACS Servers

Discussion 0
Questions 25

An engineer needs to configure a compliance policy on Cisco ISE to ensure that the latest encryption software is running on the C drive of all endpoints. Drag and drop the configuration steps from the left into the sequence on the right to accomplish this task.

Options:

Discussion 0
Questions 26

An engineer troubleshoots a new Central Web Authentication guest WLAN on a Cisco AireOS Wireless LAN Controller. Users authenticate through a self-registration portal on Cisco ISE. Guest users report these issues:

• Users can register successfully but are redirected back to the registration page.

• If a user registers, manually disconnects the device, and then reconnects, the user can access the internet.

What must be configured on the Wireless LAN Controller?

Options:

A.  

From the RADIUS Authentication Servers settings, configure a longer Server Timeout.

B.  

From the guest WLAN security settings, disable MAC filtering.

C.  

From the guest WLAN security settings, set NAC State to ISE NA

C.  

D.  

From the RADIUS Authentication Servers settings, set Support for CoA to Enabled.

Discussion 0
Questions 27

A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements:

Users and computers must be authenticated.

User groups must be retrieved during authentication.

Which protocol must be added to the allowed protocols on the policy to authenticate the users?

Options:

A.  

EAP-GTC

B.  

EAP-TLS

C.  

LEAP

D.  

MS-CHAPv2

Discussion 0
Questions 28

An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the endpoints on the network. Which node should be used to accomplish this task?

Options:

A.  

PSN

B.  

primary PAN

C.  

pxGrid

D.  

MnT

Discussion 0
Questions 29

Which two default endpoint identity groups does Cisco ISE create? (Choose two )

Options:

A.  

block list

B.  

endpoint

C.  

profiled

D.  

allow list

E.  

unknown

Discussion 0
Questions 30

A user reports that the RADIUS accounting packets are not being seen on the Cisco ISE server.

Which command is the user missing in the switch’s configuration?

Options:

A.  

radius-server vsa send accounting

B.  

aaa accounting network default start-stop group radius

C.  

aaa accounting resource default start-stop group radius

D.  

aaa accounting exec default start-stop group radios

Discussion 0
Questions 31

Which CLI command must be configured on the switchport to immediately run the MAB process if a non-802.1X capable endpoint connects to the port?

Options:

A.  

authentication order mab dot1x

B.  

authentication fallback

C.  

dot1x pae authenticator

D.  

access-session port-control auto

Discussion 0
Questions 32

An engineer tests Cisco ISE posture services on the network and must configure the compliance module to automatically download and install on endpoints Which action accomplishes this task for VPN users?

Options:

A.  

Create a Cisco AnyConnect configuration and Client Provisioning policy within Cisco ISE.

B.  

Configure the compliance module to be downloaded from within the posture policy.

C.  

Push the compliance module from Cisco FTD prior to attempting posture.

D.  

Use a compound posture condition to check for the compliance module and download if needed.

Discussion 0
Questions 33

An organization wants to enable web-based guest access for both employees and visitors The goal is to use a single portal for both user types Which two authentication methods should be used to meet this requirement? (Choose two )

Options:

A.  

LDAP

B.  

802 1X

C.  

Certificate-based

D.  

LOCAL

E.  

MAC based

Discussion 0
Questions 34

An engineer is deploying a new Cisco ISE environment for a company. The company wants the deployment to use TACACS+. The engineer verifies that Cisco ISE has a Device Administration license. What must be configured to enable TACACS+ operations?

Options:

A.  

Device Administration Work Center

B.  

Device Admin service

C.  

Device Administration Deployment settings

D.  

Device Admin Policy Sets settings

Discussion 0
Questions 35

Which platform does a Windows-based device download the Network Assistant Manager from?

Options:

A.  

Microsoft app store

B.  

Cisco Catalyst Switch

C.  

native OS

D.  

Cisco ISE

Discussion 0
Questions 36

A user misplaces a personal phone and wants to blacklist the device from accessing the company network. The company uses Cisco ISE for corporate and BYOD device authentication. Which action must the user take in Cisco ISE?

Options:

A.  

Sign in to the BYOD portal and mark the device as Lost.

B.  

Sign in to the My Devices portal and mark the device as Lost.

C.  

Sign in to the My Devices portal and mark the device as Irrecoverable.

D.  

Sign in to the BYOD portal and mark the device as Irrecoverable.

Discussion 0
Questions 37

An administrator is configuring RADIUS on a Cisco switch with a key set to Cisc403012128 but is receiving the error “Authentication failed: 22040 Wrong password or invalid shared secret. “what must be done to address this issue?

Options:

A.  

Add the network device as a NAD inside Cisco ISE using the existing key.

B.  

Configure the key on the Cisco ISE instead of the Cisco switch.

C.  

Use a key that is between eight and ten characters.

D.  

Validate that the key is correct on both the Cisco switch as well as Cisco ISE.

Discussion 0
Questions 38

Select and Place

Options:

Discussion 0
Questions 39

On which port does Cisco ISE present the Admin certificate for posture and client provisioning?

Options:

A.  

TCP/8000

B.  

TCP/8080

C.  

TCP/8905

D.  

TCP/8999

Discussion 0
Questions 40

An engineer is performing a bulk import of printer endpoints into a Cisco ISE local database by using LDAP. Which LDAP field must be configured to ensure that the devices are not profiled as Unknown?

Options:

A.  

MAC Address Object Class

B.  

MAC Address Profile Class

C.  

Profile Attribute Name

D.  

Device Profile Name

Discussion 0
Questions 41

Which two external identity stores are supported by Cisco ISE for password types? (Choose two.)

Options:

A.  

LDAP

B.  

OBDC

C.  

RADIUS Token Server

D.  

TACACS+ Token Server

E.  

SOL

Discussion 0
Questions 42

A network engineer must create a new sponsored guest portal in Cisco ISE to provide secure wireless access for company guests. All required SSL certificates, external identity sources, and identity source sequences have already been configured. Drag and drop the remaining settings into the correct configuration sequence.

Options:

A.  

Authorize the sponsored guest portal.

B.  

Configure the Sponsor Change Password Settings option.

C.  

Configure the Post-Login Banner Settings page.

D.  

Create the sponsored guest portal.

Discussion 0
Questions 43

An administrator is responsible for configuring network access for a temporary network printer. The administrator must only use the printer MAC address 50:89:65: 18:8: AB for authentication. Which authentication method will accomplish the task?

Options:

A.  

Posturing

B.  

Profiling

C.  

MAB

D.  

802.1x

Discussion 0
Questions 44

What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?

Options:

A.  

The primary node restarts

B.  

The secondary node restarts.

C.  

The primary node becomes standalone

D.  

Both nodes restart.

Discussion 0
Questions 45

What is the minimum certainty factor when creating a profiler policy?

Options:

A.  

the minimum number that a predefined condition provides

B.  

the maximum number that a predefined condition provides

C.  

the minimum number that a device certainty factor must reach to become a member of the profile

D.  

the maximum number that a device certainty factor must reach to become a member of the profile

Discussion 0
Questions 46

MacOS users are complaining about having to read through wordy instructions when remediating their workstations to gam access to the network Which alternate method should be used to tell users how to remediate?

Options:

A.  

URL link

B.  

message text

C.  

executable

D.  

file distribution

Discussion 0
Questions 47

An engineer is using the low-impact mode for a phased deployment of Cisco ISE and is trying to connect to the network prior to authentication. Which access will be denied in this?

Options:

A.  

HTTP

B.  

DNS

C.  

EAP

D.  

DHCP

Discussion 0
Questions 48

What is the deployment mode when two Cisco ISE nodes are configured in an environment?

Options:

A.  

distributed

B.  

active

C.  

standalone

D.  

standard

Discussion 0
Questions 49

A Cisco ISE administrator must restrict specific endpoints from accessing the network while in closed mode. The requirement is to have Cisco ISE centrally store the endpoints to restrict access from. What must be done to accomplish this task ' '

Options:

A.  

Add each MAC address manually to a blocklist identity group and create a policy denying access

B.  

Create a logical profile for each device ' s profile policy and block that via authorization policies.

C.  

Create a profiling policy for each endpoint with the cdpCacheDeviceld attribute.

D.  

Add each IP address to a policy denying access.

Discussion 0
Questions 50

Refer to the exhibit.

An engineer is configuring a client but cannot authenticate to Cisco ISE During troubleshooting, the show authentication sessions command was issued to display the authentication status of each port Which command gives additional information to help identify the problem with the authentication?

Options:

A.  

show authentication sessions

B.  

show authentication sessions Interface Gil/0/1 output

C.  

show authentication sessions interface Gi1/0/1 details

D.  

show authentication sessions output

Discussion 0
Questions 51

Refer to the exhibit.

An engineer is deploying 802.1X in a network that contains printers that do not support 802.1X. The current Cisco IOS switch-port configuration is shown in the exhibit. Which additional command is needed to allow the printers to authenticate?

Options:

A.  

dot1q

B.  

mab

C.  

mac

D.  

dot1x

Discussion 0
Questions 52

An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones The phones do not have the ability to authenticate via 802 1X Which command is needed on each switch port for authentication?

Options:

A.  

dot1x system-auth-control

B.  

enable bypass-mac

C.  

enable network-authentication

D.  

mab

Discussion 0
Questions 53

An employee must access the internet through the corporate network from a new mobile device that does not support native supplicant provisioning provided by Cisco ISE. Which portal must the employee use to provision to the device?

Options:

A.  

BYOD

B.  

Personal Device

C.  

My Devices

D.  

Client Provisioning

Discussion 0
Questions 54

What must be configured on the Cisco ISE authentication policy for unknown MAC addresses/identities for successful authentication?

Options:

A.  

pass

B.  

reject

C.  

drop

D.  

continue

Discussion 0
Questions 55

What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?

Options:

A.  

a primary and secondary PAN and a health check node for the Secondary PAN

B.  

a primary and secondary PAN and no health check nodes

C.  

a primary and secondary PAN and a pair of health check nodes

D.  

a primary and secondary PAN and a health check node for the Primary PAN

Discussion 0
Questions 56

An administrator must provide network access to legacy Windows endpoints with a specific device type and operating system version using Cisco ISE profiler services. The ISE profiler services and access switches must be configured to identify endpoints using the dhcp-class-identifier and parameters-request-list attributes from the DHCP traffic. These configurations were performed:

enabled the DHCP probe in Cisco ISE

configured the Cisco ISE PSN interface to receive DHCP packets

configured the attributes in custom profiling conditions

configured a custom profiling policy

configured an authorization rule with permit access

Which action completes the configuration?

Options:

A.  

Configure the switches to send copies of the DHCP traffic to the Cisco ISE PSN.

B.  

Configure the Cisco ISE PSN interface to receive SPAN DHCP traffic.

C.  

Configure the switches to relay DHCP packets to the Cisco ISE PSN.

D.  

Enable the DHCP SPAN probe in Cisco ISE primary server.

Discussion 0
Questions 57

An engineer has been tasked with standing up a new guest portal for customers that are waiting in the lobby. There is a requirement to allow guests to use their social media logins to access the guest network to appeal to more customers What must be done to accomplish this task?

Options:

A.  

Create a sponsor portal to allow guests to create accounts using their social media logins.

B.  

Create a sponsored guest portal and enable social media in the external identity sources.

C.  

Create a self-registered guest portal and enable the feature for social media logins

D.  

Create a hotspot portal and enable social media login for network access

Discussion 0
Questions 58

An administrator must change the authentication method from local accounts to SAML for wireless guest users in a Cisco ISE deployment. Using SAML, the guest portal must authenticate employees through an external identity provider. These configurations were performed:

• Created a secondary self-registered guest portal for SAML integration

• Created a primary guest portal for wireless guest users

• Configured all required settings on the SAML identity provider server

• Imported the identity provider metadata into the Cisco ISE SAML identity provider profile

Which two actions must be taken? (Choose two.)

Options:

A.  

Configure the SAML identity provider as the authentication method for the primary guest portal.

B.  

Configure the Sponsor portal.

C.  

Create a SAML identity provider in Cisco ISE.

D.  

Configure the SAML identity provider as the authentication method for the secondary guest portal.

E.  

Create employee accounts in the Sponsor portal.

Discussion 0
Questions 59

Wireless network users authenticate to Cisco ISE using 802.1X through a Cisco Catalyst switch. An engineer must create an updated configuration to assign a security group tag to the user ' s traffic using inline tagging to prevent unauthenticated users from accessing a restricted server. The configurations were performed:

• configured Cisco ISE as a Cisco TrustSec AAA server

• configured the switch as a RADIUS device in Cisco ISE

• configured the wireless LAN controller as a TrustSec device in Cisco ISE

• created a security group tog for the wireless users

• created a certificate authentication profile

■ created an identity source sequence

• assigned an appropriate security group tag to the wireless users

• defined security group access control lists to specify an egress policy

• enforced the access control lists on the TrustSec policy matrix in Cisco ISE

• configured TrustSec on the switch

• configured TrustSec on the wireless LAN controller

Which two actions must be taken to complete the configuration? (Choose two.)

Options:

A.  

Configure Security Group Tag Exchange Protocol on the wireless LAN controller.

B.  

Configure Security Group Tag Exchange Protocol to distribute IP to security group tags on Cisco ISE.

C.  

Configure inline tag propagation on the switch and wireless LAN controller.

D.  

Create static IP-to-SGT mapping for the restricted web server.

E.  

Configure Security Group Tag Exchange Protocol on the switch.

Discussion 0
Questions 60

An engineer is configuring a new Cisco ISE node. Context-sensitive information must be shared between the Cisco ISE and a Cisco ASA. Which persona must be enabled?

Options:

A.  

Administration

B.  

Policy Service

C.  

pxGrid

D.  

Monitoring

Discussion 0
Questions 61

The IT manager wants to provide different levels of access to network devices when users authenticate using TACACS+. The company needs specific commands to be allowed based on the Active Directory group membership of the different roles within the IT department. The solution must minimize the number of objects created in Cisco ISE. What must be created to accomplish this task?

Options:

A.  

one shell profile and one command set

B.  

multiple shell profiles and one command set

C.  

one shell profile and multiple command sets

D.  

multiple shell profiles and multiple command sets

Discussion 0
Questions 62

Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )

Options:

A.  

External TACACS Servers

B.  

Device Admin Service

C.  

Device Administration License

D.  

Server Sequence

E.  

Command Sets

Discussion 0
Questions 63

An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out Which configuration is causing this behavior?

Options:

A.  

One of the nodes is an active PSN.

B.  

One of the nodes is the Primary PAN

C.  

All of the nodes participate in the PAN auto failover.

D.  

All of the nodes are actively being synched.

Discussion 0
Questions 64

An administrator needs to add a new third party network device to be used with Cisco ISE for Guest and BYOD authorizations. Which two features must be configured under Network Device Profile to achieve this? (Choose two.)

Options:

A.  

dACL

B.  

TACACS

C.  

URL Redirect

D.  

SNMP community

E.  

CoA Type

Discussion 0
Questions 65

Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?

Options:

A.  

EAP server

B.  

supplicant

C.  

client

D.  

authenticator

Discussion 0
Questions 66

An organization has a fully distributed Cisco ISE deployment When implementing probes, an administrator must scan for unknown endpoints to learn the IP-to-MAC address bindings. The scan is complete on one FPSN. but the information is not available on the others. What must be done to make the information available?

Options:

A.  

Scanning must be initiated from the PSN that last authenticated the endpoint

B.  

Cisco ISE must learn the IP-MAC binding of unknown endpoints via DHCP profiling, not via scanning

C.  

Scanning must be initiated from the MnT node to centrally gather the information

D.  

Cisco ISE must be configured to learn the IP-MAC binding of unknown endpoints via RADIUS authentication, not via scanning

Discussion 0
Questions 67

The security engineer for a company has recently deployed Cisco ISE to perform centralized authentication of all network device logins using TACACS+ against the local AD domain. Some of the other network engineers are having a hard time remembering to enter their AD account password instead of the local admin password that they have used for years. The security engineer wants to change the password prompt to " Use Local AD Password: " as a way of providing a hint to the network engineers when logging in. Under which page in Cisco ISE would this change be made?

Options:

A.  

Work Centers > Device Administration > Settings > Connection Settings

B.  

Work Centers > Device Administration > Ext Id Sources > Advanced Settings

C.  

The password prompt cannot be changed on a Cisco IOS device

D.  

Work Centers > Device Administration > Network Resources > Network Devices

Discussion 0
Questions 68

An organization wants to standardize the 802 1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide What must be configured to accomplish this task?

Options:

A.  

security group tag within the authorization policy

B.  

extended access-list on the switch for the client

C.  

port security on the switch based on the client ' s information

D.  

dynamic access list within the authorization profile

Discussion 0
Questions 69

What is a difference between TACACS+ and RADIUS in regards to encryption?

Options:

A.  

TACACS+ encrypts only the password, whereas RADIUS encrypts the username and password.

B.  

TACACS+ encrypts the username and password, whereas RADIUS encrypts only the password.

C.  

TACACS+ encrypts the password, whereas RADIUS sends the entire packet in clear text.

D.  

TACACS+ encrypts the entire packet, whereas RADIUS encrypts only the password.

Discussion 0
Questions 70

An engineer is deploying Cisco ISE in a network that contains existing security products from Cisco and other vendors. The customer requires support for Cisco TrustSec and the sharing of security group tags and policy objects between Cisco ISE and the other production security products. Which persona type must be enabled on one of the Cisco ISE nodes?

Options:

A.  

SXP

B.  

Policy Service

C.  

pxGrid

D.  

Identity Mapping

Discussion 0
Questions 71

An engineer must organize endpoints in a Cisco ISE identity management store to improve the operational management of IP phone endpoints. The endpoints must meet these requirements:

• classify endpoints for finance, sales, and marketing departments

• tag each endpoint as profiled

Which action organizes the endpoints?

Options:

A.  

Create an endpoint identity group for each department with the IP phone parent group.

B.  

Create an endpoint identity group for each department with the profiled parent group.

C.  

Add a tag for the endpoints of each department and add an endpoint to profiled group.

D.  

Add a tag for the endpoints of each department and use the identity group filter.

Discussion 0
Questions 72

An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal. Which condition must be used when configuring an authorization policy that sets DenyAccess permission?

Options:

A.  

Endpoint Identity Group is Blocklist, and the BYOD state is Registered.

B.  

Endpoint Identify Group is Blocklist, and the BYOD state is Pending.

C.  

Endpoint Identity Group is Blocklist, and the BYOD state is Lost.

D.  

Endpoint Identity Group is Blocklist, and the BYOD state is Reinstate.

Discussion 0
Questions 73

A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group. Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?

Options:

A.  

Keep track of guest user activities

B.  

Configure authorization settings for guest users

C.  

Create and manage guest user accounts

D.  

Authenticate guest users to Cisco ISE

Discussion 0
Questions 74

An administrator is configuring new probes to use with Cisco ISE and wants to use metadata to help profile the endpoints. The metadata must contain traffic information relating to the endpoints instead of industry-standard protocol information Which probe should be enabled to meet these requirements?

Options:

A.  

NetFlow probe

B.  

DNS probe

C.  

DHCP probe

D.  

SNMP query probe

Discussion 0
Questions 75

Which two Cisco ISE deployment models require two nodes configured with dedicated PAN and MnT personas? (Choose two.)

Options:

A.  

three PSN nodes

B.  

seven PSN nodes with one PxGrid node

C.  

five PSN nodes with one PxGrid node

D.  

two PSN nodes with one PxGrid node

E.  

six PSN nodes

Discussion 0
Questions 76

Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two.)

Options:

A.  

hotspot

B.  

new AD user 802 1X authentication

C.  

posture

D.  

BYOD

E.  

guest AUP

Discussion 0
Questions 77

An organization is adding nodes to their Cisco ISE deployment and has two nodes designated as primary and secondary PAN and MnT nodes. The organization also has four PSNs An administrator is adding two more PSNs to this deployment but is having problems adding one of them What is the problem?

Options:

A.  

The new nodes must be set to primary prior to being added to the deployment

B.  

The current PAN is only able to track a max of four nodes

C.  

Only five PSNs are allowed to be in the Cisco ISE cube if configured this way.

D.  

One of the new nodes must be designated as a pxGrid node

Discussion 0
Questions 78

An administrator is configuring a Cisco WLC for web authentication Which two client profiling methods are enabled by default if the Apply Cisco ISE Default Settings check box has been selected ' ? (Choose two.)

Options:

A.  

CDP

B.  

DHCP

C.  

HTTP

D.  

SNMP

E.  

LLDP

Discussion 0
Questions 79

Which type of identity store allows for creating single-use access credentials in Cisco ISE?

Options:

A.  

OpenLDAP

B.  

Local

C.  

PKI

D.  

RSA SecurID

Discussion 0
Questions 80

When planning for the deployment of Cisco ISE, an organization ' s security policy dictates that they must use network access authentication via RADIUS. It also states that the deployment provide an adequate amount of security and visibility for the hosts on the network. Why should the engineer configure MAB in this situation?

Options:

A.  

The Cisco switches only support MAB.

B.  

MAB provides the strongest form of authentication available.

C.  

The devices in the network do not have a supplicant.

D.  

MAB provides user authentication.

Discussion 0
Questions 81

There are several devices on a network that are considered critical and need to be placed into the ISE database and a policy used for them. The organization does not want to use profiling. What must be done to accomplish this goal?

Options:

A.  

Enter the MAC address in the correct Endpoint Identity Group.

B.  

Enter the MAC address in the correct Logical Profile.

C.  

Enter the IP address in the correct Logical Profile.

D.  

Enter the IP address in the correct Endpoint Identity Group.

Discussion 0
Questions 82

An administrator must restrict access to the IP address of an application based on the browser version of the endpoint. Cisco ISE profiling services and guest portal access must be configured to capture the user-agent information of the endpoint from a Cisco switch using the Device Sensor feature. These configurations were performed:

• Added the switch to Cisco ISE

• Configured Device Sensor on the switch

• Enabled Cisco ISE portal access

• Configured the endpoint to connect to the Cisco ISE portal

Which type of probe must be enabled next to complete the configuration?

Options:

A.  

DHCP

B.  

RADIUS

C.  

SNMP

D.  

NetFlow

Discussion 0
Questions 83

What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?

Options:

A.  

MAB

B.  

profiling

C.  

posture

D.  

central web authentication

Discussion 0
Questions 84

An engineer needs to configure Cisco ISE Profiling Services to authorize network access for IP speakers that require access to the intercom system. This traffic needs to be identified if the ToS bit is set to 5 and the destination IP address is the intercom system. What must be configured to accomplish this goal?

Options:

A.  

NMAP

B.  

NETFLOW

C.  

pxGrid

D.  

RADIUS

Discussion 0
Questions 85

What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?

Options:

A.  

Cisco-av-pair

B.  

Class attribute

C.  

Event

D.  

State attribute

Discussion 0
Questions 86

During BYOD flow, from where does a Microsoft Windows PC download the Network Setup Assistant?

Options:

A.  

Cisco App Store

B.  

Microsoft App Store

C.  

Cisco ISE directly

D.  

Native OTA functionality

Discussion 0
Questions 87

Which three default endpoint identity groups does cisco ISE create? (Choose three)

Options:

A.  

Unknown

B.  

whitelist

C.  

end point

D.  

profiled

E.  

blacklist

Discussion 0
Questions 88

Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.

Options:

Discussion 0
Questions 89

A user changes the status of a device to stolen in the My Devices Portal of Cisco ISE. The device was originally onboarded in the BYOD wireless Portal without a certificate. The device is found later, but the user cannot re-onboard the device because Cisco ISE assigned the device to the Blocklist endpoint identity group. What must the user do in the My Devices Portal to resolve this issue?

Options:

A.  

Manually remove the device from the Blocklist endpoint identity group.

B.  

Change the device state from Stolen to Not Registered.

C.  

Change the BYOD registration attribute of the device to None.

D.  

Delete the device, and then re-add the device.

Discussion 0
Questions 90

A Cisco ISE engineer is creating a certificate authentication profile to be used with machine authentication for the network. The engineer wants to be able to compare the user-presented certificate with a certificate stored in Active Directory. What must be done to accomplish this?

Options:

A.  

Configure the user-presented password hash and a hash stored in Active Directory for comparison

B.  

Add the subject alternative name and the common name to the CAP.

C.  

Enable the option for performing binary comparison.

D.  

Use MS-CHAPv2 since it provides machine credentials and matches them to credentials stored in Active Directory

Discussion 0
Questions 91

A network engineer must enable a profiling probe. The profiling must take details through the Active Directory. Where in the Cisco ISE interface would the engineer enable the probe?

Options:

A.  

Policy > Policy Elements > Profiling

B.  

Administration > Deployment > System > Profiling

C.  

Policy > Deployment > System > Profiling

D.  

Administration > System > Deployment > Profiling

Discussion 0
Questions 92

An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+ However, the administrator must restrict certain commands based on one of three user roles that require different commands How is this accomplished without creating too many objects using Cisco ISE?

Options:

A.  

Create one shell profile and multiple command sets.

B.  

Create multiple shell profiles and multiple command sets.

C.  

Create one shell profile and one command set.

D.  

Create multiple shell profiles and one command set

Discussion 0
Questions 93

Which two actions must be verified to confirm that the internet is accessible via guest access when configuring a guest portal? (Choose two.)

Options:

A.  

The guest device successfully associates with the correct SSID.

B.  

The guest user gets redirected to the authentication page when opening a browser.

C.  

The guest device has internal network access on the WLAN.

D.  

The guest device can connect to network file shares.

E.  

Cisco ISE sends a CoA upon successful guest authentication.

Discussion 0
Questions 94

Using the SAK Active Directory Federation Services server. The configurations were performed:

• created a new SAML Identity provider profile in Cisco ISE

• exported the service provider Information

• configured all the required Active Directory Federation Services configurations

• Imported the Active Directory Federation Services metadata

• configured groups in the new SAML identity

• added attributes to the new SAML identity provider profile

• configured Advanced Settings in the new SAML identity provider profile

Which two actions must be taken to complete the configuration? (Choose two.)

Options:

A.  

Allow Kerberos single sign-on on the Sponsor portal.

B.  

Configure the Sponsor portal HTTPS port for Active Directory Federation Services integration.

C.  

Customize the Sponsor portal pages for Integration with Active Directory Federation Services.

D.  

Add SAML identity provider groups in Sponsor Group Members.

E.  

Configure an identity source sequence in the Sponsor portal.

Discussion 0
Questions 95

An engineer must configure a new authorization policy in Cisco ISE for wireless users. The policy must match a specific SSID name and use standard RADIUS attributes. The Wireless LAN Controller is already configured. Which RADIUS attribute must be configured to meet the requirement?

Options:

A.  

Airespace:Airespace-Wlan-Id

B.  

RADIUS:Calling-Station-ID

C.  

Airespace:Airespace-SSID

D.  

RADIUS:Called-Station-ID

Discussion 0
Questions 96

What is the difference between how RADIUS and TACACS+ handle encryption?

Options:

A.  

RADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields.

B.  

RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.

C.  

RADIUS only encrypts the password field, whereas TACACS+ encrypts the payload of the packet.

D.  

RADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet.

Discussion 0