[Mar 13, 2022] Latest CCNP Security 300-715 Actual Free Exam Questions
CCNP Security 300-715 Dumps Updated Practice Test and 153 unique questions
NEW QUESTION 51
An engineer is implementing Cisco ISE and needs to configure 802.1X. The port settings are configured for port-based authentication. Which command should be used to complete this configuration?
- A. aaa authentication dot1x default group radius
- B. dot1x system-auth-control
- C. dot1x pae authenticator
- D. authentication port-control auto
Answer: B
NEW QUESTION 52
What is a requirement for Feed Service to work?
- A. Cisco ISE has access to an internal server to download feed update
- B. TCP port 3080 must be opened between Cisco ISE and the feed server
- C. Cisco ISE has Internet access to download feed update
- D. Cisco ISE has a base license.
Answer: D
NEW QUESTION 53
An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. From which Cisco ISE persona should this traffic be originating?
- A. policy service
- B. authentication
- C. monitoring
- D. administration
Answer: A
NEW QUESTION 54
Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.)
- A. endpoint profile transition from Apple-Device to Apple-iPhone
- B. endpoint profile transition from Unknown to Windows 10-Workstation
- C. endpoint marked as lost in My Devices Portal
- D. updating of endpoint dACL.
- E. addition of endpoint to My Devices Portal
Answer: A,B
NEW QUESTION 55
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen What is causing this issue?
- A. The groups are present but need to be manually typed as conditions
- B. Cisco ISE's connection to the AD join point is failing
- C. The groups are not added to Cisco ISE under the AD join point
- D. Cisco ISE only sees the built-in groups, not user created ones
Answer: C
Explanation:
https://www.youtube.com/watch?v=0kuEZEo564s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION 56
Which command displays all 802 1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?
- A. show authentication sessions interface Gi 1/0/x
- B. Show authentication sessions
- C. show authentication sessions output
- D. show authentication sessions interface Gi1/0/x output
Answer: D
NEW QUESTION 57
A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group.
Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?
- A. Authenticate guest users to Cisco ISE
- B. Create and manage guest user accounts
- C. Configure authorization settings for guest users
- D. Keep track of guest user activities
Answer: C
NEW QUESTION 58
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.
Answer:
Explanation:
NEW QUESTION 59
A network administrator is setting up wireless guest access and has been unsuccessful in testing client access. The endpoint is able to connect to the SSID but is unable to grant access to the guest network through the guest portal. What must be done to identify the problem?
- A. Use context visibility to verify posture status.
- B. Use the identity group to validate the authorization rules.
- C. Use the endpoint ID to execute a session trace.
- D. Use traceroute to ensure connectivity.
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_011001.html#concept_87916A77E8774545B36D0BB422429596
NEW QUESTION 60
What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?
- A. Class attribute
- B. Event
- C. State attribute
- D. Cisco-av-pair
Answer: D
Explanation:
Section: Profiler
Explanation/Reference: https://community.cisco.com/t5/network-access-control/ise-airespace-acl-wlc-problem/td- p/2110491
NEW QUESTION 61
An organization is hosting a conference and must make guest accounts for several of the speakers attending. The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
- A. Navigate to the Sponsor Portal and suspend the guest accounts.
- B. Create an authorization rule denying sponsored guest access.
- C. Navigate to the Guest Portal and delete the guest accounts.
- D. Create an authorization rule denying guest access.
Answer: A
NEW QUESTION 62
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
- A. block list
- B. allow list
- C. profiled
- D. endpoint
- E. unknown
Answer: C,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group. These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
Workstation-An identity group that contains all the profiled workstations on your network.
NEW QUESTION 63
Refer to the exhibit. Which command is typed within the CU of a switch to view the troubleshooting output?
- A. show authentication interface gigabitethemet2/0/36
- B. show authentication registrations
- C. show authentication sessions method
- D. show authentication sessions mac 000e.84af.59af details
Answer: D
NEW QUESTION 64
Refer to the exhibit.
A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server Which two commands should be run to complete the configuration? (Choose two)
- A. radius-server attribute 8 include-in-access-req
- B. dot1x system-auth-control
- C. radius server vsa sand authentication
- D. aaa authorization auth-proxy default group radius
- E. ip device tracking
Answer: A,C
NEW QUESTION 65
Which protocol must be allowed for a BYOD device to access the BYOD portal?
- A. SSH
- B. HTTP
- C. SMTP
- D. HTTPS
Answer: A
NEW QUESTION 66
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.
Answer:
Explanation:
Monitoring = provides advanced monitoring and troubleshooting tools that you can use to effectively manage your network and resources Policy Service = provides network access, posture, guest access, client provisioning, and profiling services. This persona evaluates the policies and makes all the decisions.
Administration = manages all system-related configuration and configurations that relate to functionality such as authentication, authorization, auditing, and so on pxGrid = shares context-sensitive information from Cisco ISE to subscribers
https://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_011.html#ID57
NEW QUESTION 67
......
Verified 300-715 dumps Q&As - 100% Pass from Lead2Passed: https://certblaster.lead2passed.com/Cisco/300-715-practice-exam-dumps.html