300-715 Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :448 Q&As
  • Last Updated
    :May 25, 2026

Cisco 300-715 Online Questions & Answers

  • Question 131:

    An engineer is configuring a posture policy for Windows 10 endpoints and wants to ensure that users in each AD group have different conditions to meet to be compliant. What must be done to accomplish this task?

    A. Identify the users groups needed for different policies and create service conditions to map each one to its posture requirement.
    B. Configure a simple condition for each AD group and use it in the posture policy for each use case
    C. Use the authorization policy within the policy set to group each AD group with their respective posture policy
    D. Change the posture requirements to use an AD group lor each use case then use those requirements in the posture policy

  • Question 132:

    What is a difference between TACACS+ and RADIUS protocol traffic?

    A. TACACS+ uses UDP at the transport layer, and RADIUS uses TCP at the transport layer.
    B. TACACS+ separates each AAA function, and RADIUS combines authentication and authorization.
    C. TACACS+ encrypts passwords only, and RADIUS encrypts the entire packet payload.
    D. TACACS+ supports IP traffic only at the network layer, and RADIUS supports multiple protocols.

  • Question 133:

    An engineer tests Cisco ISE posture services on the network and must configure the compliance module to automatically download and install on endpoints. Which action accomplishes this task for VPN users?

    A. Push the compliance module from Cisco FTD prior to attempting posture.
    B. Use a compound posture condition to check for the compliance module and download, if needed.
    C. Configure the compliance module to be downloaded from within the posture policy.
    D. Create a Cisco AnyConnect configuration and Client Provisioning policy within Cisco ISE.

  • Question 134:

    A policy is being created in order to provide device administration access to the switches on a network. There is a requirement to ensure that if the session is not actively being used, after 10 minutes, it will be disconnected.

    Which task must be configured in order to meet this requirement?

    A. session timeout
    B. idle time
    C. monitor
    D. set attribute as

  • Question 135:

    An engineer is configuring a new Cisco ISE node. Context-sensitive information must be shared between the Cisco ISE and a Cisco ASA. Which persona must be enabled?

    A. pxGrid
    B. Administration
    C. Policy Service
    D. Monitoring

  • Question 136:

    Which compliance status is set when a matching posture policy has been defined for that endpomt, but all the mandatory requirements during posture assessment are not met?

    A. unauthorized
    B. untrusted
    C. non-compliant
    D. unknown

  • Question 137:

    Which two actions occur when a Cisco ISE server device administrator logs in to a device? (Choose two.)

    A. The device queries the internal identity store.
    B. The Cisco ISE server queries the internal identity store.
    C. The device queries the internal identity store.
    D. The Cisco ISE server queries the external identity store.
    E. The device queries the Cisco ISE authorization server.

  • Question 138:

    Which Cisco ISE service allows an engineer to check the compliance of endpoints before connecting to the network?

    A. personas
    B. qualys
    C. nexpose
    D. posture

  • Question 139:

    An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?

    A. ip source guard
    B. ip arp inspection
    C. ip device tracking maximum
    D. ip dhcp snooping

  • Question 140:

    What is needed to configure wireless guest access on the network?

    A. endpoint already profiled in ISE
    B. WEBAUTH ACL for redirection
    C. valid user account in Active Directory
    D. Captive Portal Bypass turned on

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.