
Easily To Pass New Cisco 300-715 Dumps with 153 Questions
Latest 300-715 Study Guides 2021 - With Test Engine PDF
The benefit in Obtaining the Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)
You earn the Cisco Certified Specialist - Security Identity Management Implementation certification.
You will have satisfied the concentration exam requirement for the new CCNP Security certification. To complete CCNP Security, you also need to pass the Implementing and Operating Cisco Security Core Technologies (350-701 SCOR) exam or its equivalent.
This exam is for:
- ISE administrators
- Network security engineers
- Cisco integrators and partners
- Wireless network security engineers
NEW QUESTION 61
A network engineer is configuring Cisco TrustSec and needs to ensure that the Security Group Tag is being transmitted between two devices Where in the Layer 2 frame should this be verified?
- A. 802.1Q filed
- B. 802.1 AE header
- C. CMD filed
- D. Payload
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/dam/global/en_ca/assets/ciscoconnect/2014/pdfs/policy_defined_segmentation_with_trustsec_rob_bleeker.pdf (slide 25)
NEW QUESTION 62
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? ()
- A. BYOD
- B. guest AUP
- C. posture
- D. hotspot
- E. new AD user 802 1X authentication
Answer: B,D
NEW QUESTION 63
Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?
- A. authenticator
- B. EAP server
- C. client
- D. supplicant
Answer: A
NEW QUESTION 64
An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE.
What must be configured within Cisco ISE to accomplish this goal?
- A. Add the root certificate authority to the trust store and enable it for authentication.
- B. Create a certificate signing request and have the root certificate authority sign it.
- C. Add an OCSP profile and configure the root certificate authority as secondary.
- D. Create an SCEP profile to link Cisco ISE with the root certificate authority.
Answer: D
Explanation:
Explanation
Ref:https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/116068-configure-pr
NEW QUESTION 65
An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?
- A. MDM
- B. Client provisioning
- C. BYOD
- D. My devices
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide
NEW QUESTION 66
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this What should be done to enable this type of posture check?
- A. Use a compound condition to look for the Windows or Mac native firewall applications.
- B. Enable the default rewall condition to check for any vendor rewall application.
- C. Use the file registry condition to ensure that the firewal is installed and running appropriately.
- D. Enable the default application condition to identify the applications installed and validade the rewall app.
Answer: B
Explanation:
Explanation
https://www.youtube.com/watch?v=6Kj8P8Hn7dY&t=109s&ab_channel=CiscoISE-IdentityServicesEngine
NEW QUESTION 67
An engineer is using Cisco ISE and configuring guest services to allow wireless devices to access the network.
Which action accomplishes this task?
- A. Create the redirect ACL on the WLC and add it to the WLC policy.
- B. Create the redirect ACL on Cisco ISE and add it to the Cisco ISE Policy.
- C. Create the redirect ACL on Cisco ISE and add it to the WLC policy.
- D. Create the redirect ACL on the WLC and add it to the Cisco ISE policy.
Answer: D
Explanation:
Section: Web Auth and Guest Services
NEW QUESTION 68
Which profiling probe collects the user-agent string?
- A. NMAP
- B. AD
- C. DHCP
- D. HTTP
Answer: D
NEW QUESTION 69
Which two roles are taken on by the administration person within a Cisco ISE distributed environment?
(Choose two.)
- A. primary
- B. active
- C. standby
- D. backup
- E. secondary
Answer: A,E
NEW QUESTION 70
What are two components of the posture requirement when configuring Cisco ISE posture? (Choose two)
- A. access policy
- B. remediation actions
- C. conditions
- D. Client Provisioning portal
- E. updates
Answer: B,C
NEW QUESTION 71
An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types. Which probe should be used to accomplish this task?
- A. DNS
- B. DHCP
- C. RADIUS
- D. MMAP
Answer: B
NEW QUESTION 72
Which personas can a Cisco ISE node assume?
- A. administration, policy service, gatekeeping
- B. policy service, gatekeeping, and monitonng
- C. administration, policy service, and monitoring
- D. administration, monitoring, and gatekeeping
Answer: C
Explanation:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html The persona or personas of a node determine the services provided by a node. An ISE node can assume any or all of the following personas: Administration, Policy Service, and Monitoring. The menu options that are available through the administrative user interface are dependent on the role and personas that an ISE node assumes. See Cisco ISE Nodes and Available Menu Options for more information.
NEW QUESTION 73
What allows an endpoint to obtain a digital certificate from Cisco ISE during a BYOD flow?
- A. My Devices Portal
- B. Application Visibility and Control
- C. Network Access Control
- D. Supplicant Provisioning Wizard
Answer: A
NEW QUESTION 74
A network administrator must use Cisco ISE to check whether endpoints have the correct version of antivirus installed Which action must be taken to allow this capability?
- A. Configure Cisco ISE to push the HostScan package to the endpoints to check for the antivirus version.
- B. Create a Cisco AnyConnect Network Visibility Module configuration profile to send the antivirus information of the endpoints to Cisco ISE.
- C. Configure a native supplicant profile to be used for checking the antivirus version
- D. Create a Cisco AnyConnect configuration within Cisco ISE for the Compliance Module and associated configuration files
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_client_prov.html About Anyconnect Network Visibility Module
https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect45/administration/guide/b_AnyConnect_Administrator_Guide_4-5/nvm.html
NEW QUESTION 75
Which of these is not a method to obtain Cisco ISE profiling data?
- A. DNS
- B. active scans
- C. Netflow
- D. HTTP
- E. RADIUS
- F. SNMP query
Answer: B
NEW QUESTION 76
When creating a policy within Cisco ISE for network access control, the administrator wants to allow different access restrictions based upon the wireless SSID to which the device is connecting. Which policy condition must be used in order to accomplish this?
- A. Radius Called-Station-ID CONTAINS <SSID Name>
- B. DEVICE Device Type CONTAINS <SSID Name>
- C. Airespace Airespace-Wlan-ld CONTAINS <SSID Name>
- D. Network Access NetworkDeviceName CONTAINS <SSID Name>
Answer: D
NEW QUESTION 77
MacOS users are complaining about having to read through wordy instructions when remediating their workstations to gam access to the network Which alternate method should be used to tell users how to remediate?
- A. URL link
- B. file distribution
- C. message text
- D. executable
Answer: A
Explanation:
https://www.sciencedirect.com/topics/computer-science/remediation-action
NEW QUESTION 78
Which three default endpoint identity groups does cisco ISE create? (Choose three )
- A. Unknown
- B. end point
- C. profiled
- D. whitelist
- E. blacklist
Answer: A,C,E
Explanation:
Explanation
Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide
NEW QUESTION 79
How is policy services node redundancy achieved in a deployment?
- A. by deploying both primary and secondary node
- B. by enabling VIP
- C. by creating a node group
- D. by utilizing RADIUS server list on the NAD
Answer: A
NEW QUESTION 80
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?
- A. session timeout
- B. termination-action
- C. radius-server timeout
- D. idle timeout
Answer: D
Explanation:
Explanation
When the inactivity timer is enabled, the switch monitors the activity from authenticated endpoints. When the inactivity timer expires, the switch removes the authenticated session. The inactivity timer for MAB can be statically configured on the switch port, or it can be dynamically assigned using the RADIUS Idle-Timeout attribute
NEW QUESTION 81
An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types.
Which probe should be used to accomplish this task?
- A. DNS
- B. DHCP
- C. NMAP
- D. RADIUS
Answer: B
Explanation:
Section: Profiler
NEW QUESTION 82
An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?
- A. MDM
- B. Client provisioning
- C. BYOD
- D. My devices
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html
NEW QUESTION 83
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for one day When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
- A. The Endpoint Purge Policy is set to 30 days for guest devices
- B. The Guest Account Purge Policy is set to 15 days
- C. The length of access is set to 7 days in the Guest Portal Settings
- D. The RADIUS policy set for guest access is set to allow repeated authentication of the same device
Answer: A
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide
NEW QUESTION 84
......
300-715 Dumps and Exam Test Engine: https://www.testinsides.top/300-715-dumps-review.html
Get New 300-715 Practice Test Questions Answers : https://drive.google.com/open?id=1kLSN9W76KlTVrx-bE1AmOdOttxiPf4Bf