لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out.Which configuration is causing this behavior?
A. ne of the nodes is the Primary PAN
B. ll of the nodes are actively being synched
C. ne of the nodes is an active PSN
D. ll of the nodes participate in the PAN auto failover
عرض الإجابة
اجابة صحيحة: A

View The Updated 300-715 Exam Questions

SPOTO Provides 100% Real 300-715 Exam Questions for You to Pass Your 300-715 Exam!

السؤال #2
An engineer must provide network access using a Cisco ISE policy that matches the identity group of endpoints unrecognized by any Cisco ISE profilers and manually adds the endpoints to a new identity group named legacy devices. These configurations were performed on the new endpoint page:- configured profiling policy- configured the legacy devices identity groupWhat must be configured next to complete the configuration?
A. ndpoint MAC address
B. ndpoint device name
C. ndpoint description
D. ndpoint operating system
عرض الإجابة
اجابة صحيحة: A
السؤال #3
An administrator connects an HP printer to a dot1x enable port, but the printer is nor accessible.Which feature must the administrator enable to access the printer?
A. change of authorization
B. MAC authentication bypass
C. TACACS authentication
D. RADIUS authentication
عرض الإجابة
اجابة صحيحة: B
السؤال #4
An engineer is using the low-impact mode for a phased deployment of Cisco ISE and is trying to connect to the network prior to authentication.Which access will be denied in this deployment?
A. DNS
B. DHCP
C. EAP
D. HTTP
عرض الإجابة
اجابة صحيحة: D
السؤال #5
A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA Which action does the CoA perform?
A. It terminates the client session
B. It applies the downloadable ACL provided in the CoA
C. It applies new permissions provided in the CoA to the client session
D. It triggers the NAD to reauthenticate the client
عرض الإجابة
اجابة صحيحة: B
السؤال #6
An administrator connects an HP printer to a dot1x enable port, but the printer is nor accessible.Which feature must the administrator enable to access the printer?
A. change of authorization
B. MAC authentication bypass
C. TACACS authentication
D. RADIUS authentication
عرض الإجابة
اجابة صحيحة: B
السؤال #7
What is the maximum number of PSN nodes supported in a medium-sized deployment?
A. two
B. three
C. five
D. eight
عرض الإجابة
اجابة صحيحة: C
السؤال #8
What is a method for transporting security group tags throughout the network?
A. by embedding the security group tag in the 802
B. by the Security Group Tag Exchange Protocol
C. by enabling 802
D. by embedding the security group tag in the IP header
عرض الإجابة
اجابة صحيحة: B
السؤال #9
Refer to the exhibit.Which switch configuration change will allow only one voice and one data endpoint on each port?
A. auto to manual
B. mab to dot1x
C. multi-auth to multi-domain
D. multi-auth to single-auth
عرض الإجابة
اجابة صحيحة: C
السؤال #10
An administrator is configuring cisco ISE lo authenticate users logging into network devices using TACACS+ The administrator is not seeing any o the authentication in the TACACS+ live logs. Which action ensures the users are able to log into the network devices?
A. AEnable the device administration service in the Administration persona
B. BEnable the session services in the administration persona
C. CEnable the service sessions in the PSN persona
D. DEnable the device administration service in the PSN persona
عرض الإجابة
اجابة صحيحة: D
السؤال #11
Which scenario does not support Cisco ISE guest services?
A. ireless LAN controller with local WebAuth
B. ired NAD with local WebAuth
C. ired NAD with central WebAuth
D. ireless LAN controller with central WebAuth
عرض الإجابة
اجابة صحيحة: D
السؤال #12
What is a requirement for Feed Service to work?
A. CP port 8080 must be opened between Cisco ISE and the feed server
B. isco ISE has access to an internal server to download feed update
C. isco ISE has a base license
D. isco ISE has Internet access to download feed update
عرض الإجابة
اجابة صحيحة: D
السؤال #13
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two.)
A. subscriber
B. primary
C. administration
D. publisher
E. policy service
عرض الإجابة
اجابة صحيحة: CE
السؤال #14
Refer to the exhibit:Which command is typed within the CU of a switch to view the troubleshooting output?
A. how authentication sessions mac 000e
B. how authentication registrations
C. how authentication interface gigabitethemet2/0/36
D. how authentication sessions method
عرض الإجابة
اجابة صحيحة: A
السؤال #15
An administrator connects an HP printer to a dot1x enable port, but the printer is nor accessible.Which feature must the administrator enable to access the printer?
A. change of authorization
B. MAC authentication bypass
C. TACACS authentication
D. RADIUS authentication
عرض الإجابة
اجابة صحيحة: B
السؤال #16
Which two actions occur when a Cisco ISE server device administrator logs in to a device? (Choose two.)
A. The Cisco ISE server queries the internal identity store
B. The device queries the external identity store
C. The device queries the Cisco ISE authorization server
D. The device queries the internal identity store
E. The Cisco ISE server queries the external identity store
عرض الإجابة
اجابة صحيحة: AE
السؤال #17
What are two benefits of TACACS+ versus RADIUS for device administration? (Choose two )
A. ACACS+ supports 802
B. ACACS+ uses UDP, and RADIUS uses TCP
C. ACACS+ has command authorization, and RADIUS does not
D. ACACS+ provides the service type, and RADIUS does not
E. ACACS+ encrypts the whole payload, and RADIUS encrypts only the password
عرض الإجابة
اجابة صحيحة: CE
السؤال #18
An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.What must be configured to accomplish this task?
A. dynamic access list within the authorization profile
B. extended access-list on the switch for the client
C. security group tag within the authorization policy
D. port security on the switch based on the client’s information
عرض الإجابة
اجابة صحيحة: A
السؤال #19
A network administrator is configuring a new access switch to use with Cisco ISE for network access control. There is a need to use a centralized server for the reauthentication timers.What must be configured in order to accomplish this task?
A. Issue the authentication timer reauthenticate server command on the switch
B. Configure Cisco ISE to block access after a certain period of time
C. Configure Cisco ISE to replace the switch configuration with new timers
D. Issue the authentication periodic command on the switch
عرض الإجابة
اجابة صحيحة: A
السؤال #20
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the main deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out.Which configuration is causing this behavior?
A. All of the nodes are actively being synched
B. All of the nodes participate in the PAN auto failover
C. One of the nodes is an active PSN
D. One of the nodes is the Primary PAN
عرض الإجابة
اجابة صحيحة: D
السؤال #21
In which two ways can users and endpoints be classified for TrustSec? (Choose two.)
A. VLAN
B. dynamic
C. QoS
D. SGACL
E. SXP
عرض الإجابة
اجابة صحيحة: AB
السؤال #22
Which personas can a Cisco ISE node assume?
A. policy service, gatekeeping, and monitoring
B. administration, monitoring, and gatekeeping
C. administration, policy service, and monitoring
D. administration, policy service, gatekeeping
عرض الإجابة
اجابة صحيحة: C
السؤال #23
A network security administrator must integrate Cisco ISE with Active Directory. The administrator must carry out a join operation.Which action must the security administrator take?
A. Search Active Directory to see if admin user account exists
B. Remove the ISE machine account from the domain
C. Join Cisco ISE to the Active Directory domain
D. Remove Cisco ISE user account from the domain
عرض الإجابة
اجابة صحيحة: C
السؤال #24
An engineer is configuring a guest password policy and needs to ensure that the password complexity requirements are set to mitigate brute force attacks.Which two requirements should be included in this policy? (Choose two.)
A. active username limit
B. password expiration period
C. access code control
D. username expiration date
E. minimum password length
عرض الإجابة
اجابة صحيحة: BE
السؤال #25
Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue.
A. Enable IPC access over port 80
B. Ensure that the NAT address is properly configured
C. Establish access to one Global Catalog server
D. Provide domain administrator access to Active Directory
E. Configure a secure LDAP connection
عرض الإجابة
اجابة صحيحة: CD
السؤال #26
An organization is adding nodes to their Cisco ISE deployment and has two nodes designated as primary and secondary PAN and MnT nodes. The organization also has four PSNs. An administrator is adding two more PSNs to this deployment but is having problems adding one of them.What is the problem?
A. Only five PSNs are allowed to be in the Cisco ISE cube if configured this way
B. One of the new nodes must be designated as a pxGrid node
C. The new nodes must be set to primary prior to being added to the deployment
D. The current PAN is only able to track a max of four nodes
عرض الإجابة
اجابة صحيحة: A
السؤال #27
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?
A. The secondary node restarts
B. The primary node restarts
C. Both nodes restart
D. The primary node becomes standalone
عرض الإجابة
اجابة صحيحة: A
السؤال #28
Which command displays all 802.1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?
A. how authentication sessions interface Gi1/0/x output
B. how authentication sessions
C. how authentication sessions output
D. how authentication sessions interface Gi 1/0/x
عرض الإجابة
اجابة صحيحة: B
السؤال #29
Refer to the exhibit.In which scenario does this switch configuration apply?
A. when allowing a hub with multiple clients connected
B. when allowing multiple IP phones to be connected
C. when preventing users with hypervisor
D. when bypassing IP phone authentication
عرض الإجابة
اجابة صحيحة: A
السؤال #30
A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution must meet these requirements:- Users and computers must be authenticated.- User groups must be retrieved during authentication.Which protocol must be added to the allowed protocols on the policy to authenticate the users?
A. AP-GTC
B. S-CHAPv2
C. AP-TLS
D. EAP
عرض الإجابة
اجابة صحيحة: B
السؤال #31
Which command displays all 802.1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?
A. show authentication sessions interface Gi1/0/x output
B. show authentication sessions
C. show authentication sessions output
D. show authentication sessions interface Gi 1/0/x
عرض الإجابة
اجابة صحيحة: B
السؤال #32
An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.What must be configured to accomplish this task?
A. dynamic access list within the authorization profile
B. extended access-list on the switch for the client
C. security group tag within the authorization policy
D. port security on the switch based on the client’s information
عرض الإجابة
اجابة صحيحة: A
السؤال #33
Which two VMware features are supported on a Cisco ISE virtual appliance? (Choose two.)
A. VM cold migration
B. OVF support
C. multivendor integration
D. VM hardware version 7+
E. VM snapshots
عرض الإجابة
اجابة صحيحة: AB
السؤال #34
What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?
A. a primary and secondary PAN and a health check node for the Secondary PAN
B. a primary and secondary PAN and no health check nodes
C. a primary and secondary PAN and a pair of health check nodes
D. a primary and secondary PAN and a health check node for the Primary PAN
عرض الإجابة
اجابة صحيحة: D
السؤال #35
What should be configured on the Cisco ISE authentication policy for unknown MAC addresses/identities for successful authentication?
A. continue
B. pass
C. drop
D. reject
عرض الإجابة
اجابة صحيحة: A
السؤال #36
Refer to the exhibit.In which scenario does this switch configuration apply?
A. when allowing a hub with multiple clients connected
B. when allowing multiple IP phones to be connected
C. when preventing users with hypervisor
D. when bypassing IP phone authentication
عرض الإجابة
اجابة صحيحة: A
السؤال #37
What must match between Cisco ISE and the network access device to successfully authenticateendpoints?
A. NMP version
B. hared secret
C. ertificate
D. rofile
عرض الإجابة
اجابة صحيحة: B
السؤال #38
What is a requirement for Feed Service to work?
A. TCP port 8080 must be opened between Cisco ISE and the feed server
B. Cisco ISE has access to an internal server to download feed update
C. Cisco ISE has a base license
D. Cisco ISE has Internet access to download feed update
عرض الإجابة
اجابة صحيحة: D
السؤال #39
An administrator connects an HP printer to a dot1x enable port, but the printer is nor accessible.Which feature must the administrator enable to access the printer?
A. change of authorization
B. MAC authentication bypass
C. TACACS authentication
D. RADIUS authentication
عرض الإجابة
اجابة صحيحة: B
السؤال #40
Which Cisco ISE deployment model provides redundancy by having every node in the deployment configured with the Administration, Policy Service, and Monitoring personas to protect from a complete node failure?
A. dispersed
B. distributed
C. two-node
D. hybrid
عرض الإجابة
اجابة صحيحة: C
السؤال #41
What is a requirement for Feed Service to work?
A. TCP port 8080 must be opened between Cisco ISE and the feed server
B. Cisco ISE has access to an internal server to download feed update
C. Cisco ISE has a base license
D. Cisco ISE has Internet access to download feed update
عرض الإجابة
اجابة صحيحة: D
السؤال #42
An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as "Medical Switch" so that the policies can be made separately for the endpoints connecting through them. Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal?
A. Change the device type to Medical Switch
B. Change the device profile to Medical Switch
C. Change the model name to Medical Switch
D. Change the device location to Medical Switch
عرض الإجابة
اجابة صحيحة: A
السؤال #43
Refer to the exhibit.Which switch configuration change will allow only one voice and one data endpoint on each port?
A. auto to manual
B. mab to dot1x
C. multi-auth to multi-domain
D. multi-auth to single-auth
عرض الإجابة
اجابة صحيحة: C
السؤال #44
An engineer is configuring Central Web Authentication in Cisco ISE to provide guest access. When an authentication rule is configured in the Default Policy Set for the Wired_MAB or Wireless_MAB conditions, what must be selected for the "if user not found" setting?
A. CONTINUE
B. REJECT
C. ACCEPT
D. DROP
عرض الإجابة
اجابة صحيحة: A
السؤال #45
A network engineer has been tasked with enabling a switch to support standard web authentication for Cisco ISE. This must include the ability to provision for URL redirection on authentication Which two commands must be entered to meet this requirement? (Choose two)
A. Ip http secure-authentication
B. Ip http server
C. Ip http redirection
D. Ip http secure-server
E. Ip http authentication
F. Reveal Answer
عرض الإجابة
اجابة صحيحة: BD
السؤال #46
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users fromthe Cisco ISE node?
A. ession timeout
B. dle timeout
C. adius-server timeout
D. ermination-action
عرض الإجابة
اجابة صحيحة: B
السؤال #47
What is the deployment mode when two Cisco ISE nodes are configured in an environment?
A. standalone
B. distributed
C. standard
D. active
عرض الإجابة
اجابة صحيحة: B
السؤال #48
A network security administrator must integrate Cisco ISE with Active Directory. The administrator must carry out a leave operation.Which action on Active Directory is needed to meet the requirement?
A. Remove the ISE machine account from the domain
B. Remove the ISE user account from the domain
C. Create ISE machine account to domain
D. Search Active Directory to see if admin user account exists
عرض الإجابة
اجابة صحيحة: A
السؤال #49
What is used by the CA to issue a certificate to an endpoint?
A. device network address
B. device unique identifier
C. certificate template
D. certificate provisioning portal
عرض الإجابة
اجابة صحيحة: C
السؤال #50
A network security administrator wants to integrate Cisco ISE with Active Directory.Which configuration action must the security administrator take to accomplish the task?
A. Search Active Directory to see if admin user account exists
B. Remove the ISE machine account from the domain
C. Remove Cisco ISE user account from the domain
D. Join Cisco ISE to the Active Directory domain
عرض الإجابة
اجابة صحيحة: D
السؤال #51
What does a fully distributed Cisco ISE deployment include?
A. PAN and PSN on the same node while MnTs are on their own dedicated nodes
B. PAN and MnT on the same node while PSNs are on their own dedicated nodes
C. All Cisco ISE personas on their own dedicated nodes
D. All Cisco ISE personas are sharing the same node
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: A
السؤال #52
What is the difference between how RADIUS and TACACS+ handle encryption?
A. RADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet
B. RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field
C. RADIUS only encrypts the password field, whereas TACACS+ encrypts the payload of packet
D. RADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields
E. Reveal Answer
عرض الإجابة
اجابة صحيحة: C
السؤال #53
A network engineer must enforce access control using special tags, without re-engineering the network design.Which feature should be configured to achieve this in a scalable manner?
A. BAC
B. ACL
C. GT
D. LAN
عرض الإجابة
اجابة صحيحة: C
السؤال #54
Which two methods should a sponsor select to create bulk guest accounts from the sponsor portal?(Choose two )
A. andom
B. onthly
C. aily
D. mported
E. nown
عرض الإجابة
اجابة صحيحة: AD
السؤال #55
An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the used to accomplish this task?
A. policy service
B. monitoring
C. pxGrid
D. primary policy administrator
عرض الإجابة
اجابة صحيحة: B
السؤال #56
A network security engineer needs to configure 802.1X port authentication to allow a single host to be authenticated for data and another single host to be authenticated for voice.Which command should the engineer run on the interface to accomplish this goal?
A. authentication host-mode multi-domain
B. authentication host-mode single-host
C. authentication host-mode multi-auth
D. authentication host-mode multi-host
عرض الإجابة
اجابة صحيحة: A
السؤال #57
What are two components of the posture requirement when configuring Cisco ISE posture? (Choose two)
A. updates
B. remediation actions
C. Client Provisioning portal
D. conditions
E. access policy
عرض الإجابة
اجابة صحيحة: BD
السؤال #58
Which interface-level command is needed to turn on 802.1X authentication?
A. dot1x system-auth-control
B. dot1x pae authenticator
C. aaa server radius dynamic-author
D. authentication host-mode single-host
عرض الإجابة
اجابة صحيحة: B
السؤال #59
A network engineer is attempting to terminate and reinitialize wireless user sessions individually by using the Live Sessions tab in Cisco ISE. Cisco ISE and the Cisco WLC are separated by a firewall.Which port must be allowed on the firewall so that the network engineer can perform this function from Cisco ISE?
A. TCP port 8443
B. UDP port 5246
C. UDP port 1700
D. TCP port 3791
عرض الإجابة
اجابة صحيحة: C

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us