Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.)
Reveal answer details Close answer details
Correct answersC, D
Cisco · 300-715
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Multiple choice
Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.) Reveal answer details Close answer detailsCorrect answersC, D
Multiple choice
Which two default endpoint identity groups does Cisco ISE create? (Choose two ) Reveal answer details Close answer detailsCorrect answersA, D Explanation Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system. Cisco ISE creates the following endpoint identity groups: 1. Blacklist--This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group. In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group: 1. Cisco-IP-Phone--An identity group that contains all the profiled Cisco IP phones on your network. https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/
Single choice
Refer to the exhibit. ![]() Which component must be configured to apply the SGACL? Reveal answer details Close answer detailsCorrect answerA Explanation https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/arch_over.html#52796
Single choice
What happens when an internal user is configured with an external identity store for authentication, but an engineer uses the Cisco ISE admin portal to select an internal identity store as the identity source? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which two tasks must be completed when configuring the Cisco ISE BYOD Portal? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Single choice
The profiling data from network access devices is sent to which Cisco ISE node? Reveal answer details Close answer detailsCorrect answerD
Single choice
An administrator must restrict access to the IP address of an application based on the browser version of the endpoint. Cisco ISE profiling services and quest portal access must be configured to capture the user-agent. Information of the endpoint from a Cisco switch using the Device Sensor feature. These configurations were performed: 1. added the switch to Cisco ISE Which type of probe must be enabled next to complete the configuration? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Wireless network users authenticate to Cisco ISE using 802.1X through a Cisco Catalyst switch. An engineer must create an updated configuration to assign a security group tag to the user's traffic using inline tagging to prevent unauthenticated users from accessing a restricted server. The configurations were performed: configured Cisco ISE as a Cisco TrustSec AAA server configured the switch as a RADIUS device in Cisco ISE configured the wireless LAN controller as a TrustSec device in Cisco ISE created a security group tag for the wireless users created a certificate authentication profile created an identity source sequence assigned an appropriate security group tag to the wireless users defined security group access control lists to specify an egress policy enforced the access control lists on the TrustSec policy matrix in Cisco ISE configured TrustSec on the switch configured TrustSec on the wireless LAN controller Which two actions must be taken to complete the configuration? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, D
Single choice
An engineer is configuring 802.1X and is testing out their policy sets. After authentication, some endpoints are given an access-reject message but are still allowed onto the network. What is causing this issue to occur? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which three default endpoint identity groups does cisco ISE create? (Choose three) Reveal answer details Close answer detailsCorrect answersA, D, E Explanation Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP- https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_010101.html#ID1678
Single choice
Which deployment mode allows for one or more policy service nodes to be used for session failover? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is a function of client provisioning? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
An administrator is adding a switch to the network that is running cisco ISE and is only for IP phones. the phones do not have the ability to authenticate via 802.1x. Which command is needed on each switch port for authentication? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Refer to the exhibit. ![]() A network engineers configuring the switch to accept downloadable ACLs from a Cisco ISC server. Which two commands should be run to complete the configuration? (Choose two) Reveal answer details Close answer detailsCorrect answersD, E
Single choice
The IT manager wants to provide different levels of access to network devices when users authenticate using TACACS+. The company needs specific commands to be allowed based on the Active Directory group membership of the different roles within the IT department. The solution must minimize the number of objects created in Cisco ISE. What must be created to accomplish this task? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which Cisco ISE component intercepts HTTP and HTTPS requests and redirects them to the Guest User Portal? Reveal answer details Close answer detailsCorrect answerA
Single choice
An engineer is deploying a new Cisco ISE environment for a company. The company wants the deployment to use TACACS+. The engineer verifies that Cisco ISE has a Device Administration license. What must be configured to enable TACACS+ operations? Reveal answer details Close answer detailsCorrect answerB
Single choice
A laptop was stolen and a network engineer added it to the block list endpoint identity group What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access? Reveal answer details Close answer detailsCorrect answerC Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/
Single choice
An engineer needs to configure a Cisco ISE server to issue a CoA for endpoints already authenticated to access the network. The CoA option must be enforced on a session, even if there are multiple active sessions on a port. What must be configured to accomplish this task? Reveal answer details Close answer detailsCorrect answerA
Single choice
The security team wants to secure the wired network. A legacy printer on the network with the MAC address 00:43:08:50:64:60 does not support 802.1X. Which setting must be enabled in the Allowed Authentication Protocols list in your Authentication Policy for Cisco ISE to support MAB for this MAC address? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
A network engineer must enforce access control using special tags, without re-engineering the network design. Which feature should be configured to achieve this in a scalable manner? Reveal answer details Close answer detailsCorrect answerA
Drag & drop
DRAG DROP A security engineer configures a Cisco Catalyst switch to use Cisco TrustSec. The engineer must define the PAC key to authenticate the switch to Cisco ISE. Drag and drop the commands from the left into sequence on the right. Not all options are used. ![]() Reveal answer details Close answer details![]()
Multiple choice
An administrator is configuring the Native Supplicant Profile to be used with the Cisco ISE posture agents and needs to test the connection using wired devices to determine which profile settings are available. Which two configuration settings should be used to accomplish this task? (Choose two.) Reveal answer details Close answer detailsCorrect answersC, E
Multiple choice
A network engineer has been tasked with enabling a switch to support standard web authentication for Cisco ISE. This must include the ability to provision for URL redirection on authentication. Which two commands must be entered to meet this requirement? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
An employee must access the internet through the corporate network from a new mobile device that does not support native supplicant provisioning provided by Cisco ISE. Which portal must the employee use to provision to the device? Reveal answer details Close answer detailsCorrect answerA
Drag & drop
DRAG DROP Drag and drop the configuration steps from the left into the sequence on the right to install two Cisco ISE nodes in a distributed deployment. ![]() Reveal answer details Close answer details![]()
Multiple choice
A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.) Reveal answer details Close answer detailsCorrect answersC, E
Multiple choice
An administrator is configuring a Cisco WLC for web authentication. Which two client profiling methods are enabled by default if the Apply Cisco ISE Default Settings check box has been selected'? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, C
Single choice
What is a difference between TACACS+ and RADIUS protocol traffic? Reveal answer details Close answer detailsCorrect answerB
Single choice
A security administrator is using Cisco ISE to create a BYOD onboarding solution for all employees who use personal devices on the corporate network. The administrator generates a Certificate Signing Request and signs the request using an external Certificate Authority server. Which certificate usage option must be selected when importing the certificate into ISE? Reveal answer details Close answer detailsCorrect answerC
Single choice
An administrator must enable scanning for specific endpoints when they attempt to access the network. Which action accomplishes this task? Reveal answer details Close answer detailsCorrect answerB
Single choice
An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types. Which probe should be used to accomplish this task? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which compliance status is set when a matching posture policy has been defined for that endpomt, but all the mandatory requirements during posture assessment are not met? Reveal answer details Close answer detailsCorrect answerC
Single choice
A network engineer is implementing cisco ISE and needs to configure 802.1x. the ports settings are configured for port-based authentication. Which command should be used to complete this configuration? Reveal answer details Close answer detailsCorrect answerB Explanation https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sg/configuration/guide/conf/dot1x.html#wp1133395
Single choice
An organization is adding nodes to their Cisco ISE deployment and has two nodes designated as primary and secondary PAN and MnT nodes. The organization also has four PSNs An administrator is adding two more PSNs to this deployment but is having problems adding one of them What is the problem? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
What are two benefits of TACACS+ versus RADIUS for device administration? (Choose two ) Reveal answer details Close answer detailsCorrect answersC, E
Single choice
Refer to the exhibit ![]() Which switch configuration change will allow only one voice and one data endpoint on each port? Reveal answer details Close answer detailsCorrect answerA Explanation https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907
Single choice
An administrator connects an HP printer to a dot1x enable port, but the printer in not accessible. Which feature must the administrator enable to access the printer? Reveal answer details Close answer detailsCorrect answerA Explanation https://community.cisco.com/t5/network-access-control/ise-for-printer-security/m-p/3933216
Single choice
A network administrator must configura endpoints using an 802 1X authentication method with EAP identity certificates that are provided by the Cisco ISE When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network Which EAP type must be configured by the network administrator to complete this task? Reveal answer details Close answer detailsCorrect answerD Explanation https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/certificate-requirements-eap-tls-peap
Multiple choice
Which two ports do network devices typically use for CoA? (Choose two ) Reveal answer details Close answer detailsCorrect answersD, E
Single choice
Which Cisco ISE service allows an engineer to check the compliance of endpoints before connecting to the network? Reveal answer details Close answer detailsCorrect answerD Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/ Posture is a service in Cisco Identity Services Engine (Cisco ISE) that allows you to check the state, also known as posture, of all the endpoints that are connecting to a network for compliance with corporate security policies. This allows you to control clients to access protected areas of a network.
Single choice
The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectively restrict network access for this endpoint? Reveal answer details Close answer detailsCorrect answerC Explanation Cisco ISE provides a feature called Adaptive Network Control (ANC) that allows administrators to apply policies to endpoints based on their behavior or status 1. One of the ANC policies is Quarantine, which restricts network access for an endpoint by assigning it to a limited-access VLAN or applying an access control list (ACL) on the switch port 2. To use the Quarantine policy, the administrator must add the MAC address of the rogue endpoint to the endpoint quarantine list in ISE2. This will trigger a change of authorization (CoA) for the endpoint and apply the Quarantine policy. The other options are not effective for restricting network access for a rogue endpoint, as they do not use the ANC feature of ISE.
Single choice
An administrator must onboard MacOS endpoints that connect to Cisco switches using the BYOD portal in Cisco ISE. The authentication method must be configured to meet these requirements: 1. Cisco ISE identifies itself by providing its identity certificate to the endpoint. Which protocol must be configured? Reveal answer details Close answer detailsCorrect answerA Explanation The described onboarding process requires mutual authentication between the endpoint and Cisco ISE using certificates. The Extensible Authentication Protocol - Transport Layer Security (EAP-TLS) protocol is the best choice because it supports: TLS ensures that communication between the client and server is encrypted and secure.
Single choice
What is the Cisco ISE default admin login name and password? Reveal answer details Close answer detailsCorrect answerC
Single choice
A network administrator is configuring a secondary Cisco ISE node from the backup configuration of the primary Cisco ISE node to create a high availability pair. The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE. Which command must be issued for this to work? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
An administrator is configuring a Cisco ISE posture agent in the client provisioning policy and needs to ensure that the posture policies that interact with clients are monitored, and end users are required to comply with network usage rules Which two resources must be added in Cisco ISE to accomplish this goal? (Choose two) Reveal answer details Close answer detailsCorrect answersA, E Explanation https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide4-0/configure-posture.html
Multiple choice
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose 2) Reveal answer details Close answer detailsCorrect answersB, C
Multiple choice
A network engineer needs to ensure that the access credentials are not exposed during the 802.1x authentication among components. Which two protocols should complete this task? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, D
Single choice
A policy is being created in order to provide device administration access to the switches on a network. Which task must be configured in order to meet this requirement? Reveal answer details Close answer detailsCorrect answerA Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_admin_accesspolicy_settings.html#reference_0E24B8FBFAB248219E1194435670347F
Single choice
An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE? Reveal answer details Close answer detailsCorrect answerB Explanation When using separate PSNs for different sites, the network device must be added to all PSN nodes in the deployment, so that the device can communicate with the appropriate PSN based on the location of the user 1. If the device is not added to all PSN nodes, the user may encounter an EAP-TLS authentication failure when moving between sites, as the device may not be able to reach the PSN that issued the certificate 2. The other options are not relevant for this scenario, as they do not address the issue of PSN communication.
Single choice
Which statement is true? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which two endpoint compliance statuses are possible? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, D
Multiple choice
An engineer is using profiling to determine what access an endpoint must receive. After configuring both Cisco ISE and the network devices for 802.1X and profiling, the endpoints do not profile prior to authentication. What are two reasons this is happening? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, E
Single choice
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure? Reveal answer details Close answer detailsCorrect answerC
Single choice
An engineer must use certificate authentication for endpoints that connect to a wired network with a Cisco ISE deployment. The engineer must define the certificate field used as the principal username. What is needed to complete the configuration? Reveal answer details Close answer detailsCorrect answerD
Single choice
An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as "Medical Switch" so that the policies can be made separately for the endpoints connecting through them. Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which valid external identity source can be used with Cisco ISE? Reveal answer details Close answer detailsCorrect answerB
Single choice
A user reports that the RADIUS accounting packets are not being seen on the Cisco ISE server. Which command is the user missing in the switch's configuration? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which file extension is required when deploying Cisco ISE using a ZTP configuration file in Microsoft Hyper-V? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is a difference between TACACS+ and RADIUS in regards to encryption? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
Which of these is not a method to obtain Cisco ISE profiling data? Reveal answer details Close answer detailsCorrect answerD
Single choice
A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA Which action does the CoA perform? Reveal answer details Close answer detailsCorrect answerD Explanation https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-
Single choice
An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. Reveal answer details Close answer detailsCorrect answerB
Multiple choice
An administrator must configure Cisco ISE to authenticate a user accessing a Cisco Adaptive Security Appliance firewall using SSH. The solution must meet these requirements: 1. The local Cisco ISE database must be used for user authentication The configurations were performed: Which two actions must be taken in Cisco ISE? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, D
Drag & drop
DRAG DROP Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night. ![]() Reveal answer details Close answer details![]() Explanation https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/ Choose Administration > System > Deployment.
Single choice
A network engineer is configuring a new certificate template on the internal CA within Cisco ISE to provision certificates to BYOD devices that must be enrolled in the network. What must be configured in the SAN field of the certificate to identify the devices after enrollment? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which scenario does not support Cisco ISE guest services? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
An administrator must configure Cisco ISE to send CoA requests to a Cisco switch using SNMP. These configurations were performed: 1. enabled SNMP on the switch Which two configurations must be performed to send the CoA requests? (Choose two.) Reveal answer details Close answer detailsCorrect answersB, E Explanation Configure the SNMP server in Cisco ISE 1. Cisco ISE must be set up to communicate with the switch using SNMP for CoA requests. Select the CoA type as SNMP in the network device profile 1. The network device profile in Cisco ISE determines how CoA requests are sent to the network device. |