300-715 Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :448 Q&As
  • Last Updated
    :May 25, 2026

Cisco 300-715 Online Questions & Answers

  • Question 101:

    A user changes the status of a device to stolen in the My Devices Portal of Cisco ISE. The device was originally onboarded in the BYOD wireless Portal without a certificate. The device is found later, but the user cannot re-onboard the device because Cisco ISE assigned the device to the Blocklist endpoint identity group. What must the user do in the My Devices Portal to resolve this issue?

    A. Manually remove the device from the Blocklist endpoint identity group.
    B. Change the device state from Stolen to Not Registered.
    C. Change the BYOD registration attribute of the device to None.
    D. Delete the device, and then re-add the device.

  • Question 102:

    An engineer must configure an HTTP probe on a Cisco ISE virtual appliance running on VMWare using a dedicated interface for profiling. The interface is assigned to the VM Network port group. The engineer is logged into the hypervisor with a user account that only provides access to the Cisco ISE VM and the network settings for the VM.

    Which security setting must be changed for this interface to accept SPAN traffic?

    A. Set Promiscuous mode to inherit from vSwitch in the Port Group properties.
    B. Set Promiscuous mode to inherit from Port Group in the vSwitch properties.
    C. Set Promiscuous mode to Accept in the Port Group properties.
    D. Set Promiscuous mode to Accept in the vSwitch properties.

  • Question 103:

    Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?

    (Choose two.)

    A. Firepower
    B. WLC
    C. IOS
    D. ASA
    E. Shell

  • Question 104:

    An engineer wants to preselect AD groups to be used in the access policy after integrating Cisco ISE with an active directory. Which configuration steps must the engineer take to assign groups to the AD on the identity management page?

    A. external identity sources > active directory > groups
    B. user identity groups > groups
    C. external identity sources > groups > active directory
    D. groups > user identity groups

  • Question 105:

    An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

    A. VLAN to SGT mapping
    B. IP Address to SGT mapping
    C. L3IF to SGT mapping
    D. Subnet to SGT mapping

  • Question 106:

    MacOS users are complaining about having to read through wordy instructions when remediating their workstations to gam access to the network Which alternate method should be used to tell users how to remediate?

    A. URL link
    B. message text
    C. executable
    D. file distribution

  • Question 107:

    A security administrator is using Cisco ISE to create a BYOD onboarding solution for all employees who use personal devices on the corporate network. The administrator generates a Certificate Signing Request and signs the request using an external Certificate Authority server. Which certificate usage option must be selected when importing the certificate into ISE?

    A. RADIUS
    B. DLTS
    C. Portal
    D. Admin

  • Question 108:

    An organization is using Cisco ISE to provide AAA services to non-Cisco switches with IP phones connected. An engineer needs to use Profiling Services to authorize network access for IP phones that do not support 802.1X. What must be configured to accomplish this goal?

    A. DHCP
    B. SNMPTRAP
    C. SNMPQUERY
    D. RADIUS

  • Question 109:

    An engineer needs to configure a Cisco ISE server to issue a CoA for endpoints already authenticated to access the network. The CoA option must be enforced on a session, even if there are multiple active sessions on a port. What must be configured to accomplish this task?

    A. the Reauth CoA option in the Cisco ISE system profiling settings enabled
    B. an endpoint profiling policy with the No CoA option enabled
    C. an endpoint profiling policy with the Port Bounce CoA option enabled
    D. the Port Bounce CoA option in the Cisco ISE system profiling settings enabled

  • Question 110:

    An administrator must configure Cisco ISE profiling services and the Cisco switch device sensor feature to provide user access using the AD-Join-Point and AD-Operating-System attributes from the Active Directory Probe. These configurations were performed:

    1.

    configured all the required Cisco Wireless LAN Controller configurations

    2.

    enabled Active Directory probes

    3.

    configured a custom profiling policy

    4.

    joined Cisco ISE to Active Directory

    5.

    configured the authorization rule with full access permission

    Which two actions complete the configuration? (Choose two.)

    A. Configure an identity group for endpoints.
    B. Enable the SNMP probe.
    C. Configure a profiling logical profile.
    D. Configure custom profiling conditions.
    E. Enable the RADIUS probe.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.