300-715 Self-Study Guide for Becoming an Implementing and Configuring Cisco Identity Services Engine Expert [Q126-Q149]

Share

300-715 Self-Study Guide for Becoming an Implementing and Configuring Cisco Identity Services Engine Expert

300-715 Study Guide Realistic Verified 300-715 Dumps


Understanding functional and technical aspects of Implementing and Configuring Cisco Identity Services Engine (300-715 SISE) BYOD

The following will be discussed in CISCO 300-715 exam dumps pdf:

  • Configure Posture Policies
  • Configure Client Provisioning
  • Configure Access Policy for Easy Connect
  • Configure web authentication
  • Access the SISE Lab and Install ISE 2.4
  • Configure TACACS+ Command Authorization
  • Configure BYOD
  • Configure Initial Cisco ISE Setup, GUI Familiarization, and System Certificate Usage
  • Configure Guest Access
  • Configure Guest Access Operations
  • Configure Basic Policy on Cisco ISE
  • Configure Cisco ISE Compliance Services
  • Configure Cisco ISE for Basic Device Administration
  • Configure Profiling

 

NEW QUESTION 126
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node ,s deregistered?

  • A. Both nodes restart.
  • B. The primary node becomes standalone
  • C. The secondary node restarts.
  • D. The primary node restarts

Answer: A

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-1-
1/installation_guide/ise_install_guide/ise_deploy.html
if your deployment has two nodes and you deregister the secondary node, both nodes in this primary- secondary pair are restarted. (The former primary and secondary nodes become standalone.)

 

NEW QUESTION 127
Which three default endpoint identity groups does cisco ISE create? (Choose three)

  • A. end point
  • B. profiled
  • C. blacklist
  • D. Unknown
  • E. whitelist

Answer: B,C,D

Explanation:
Default Endpoint Identity Groups Created for Endpoints
Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_010101.html#ID1678

 

NEW QUESTION 128
What must match between Cisco ISE and the network access device to successfully authenticate endpoints?

  • A. certificate
  • B. shared secret
  • C. SNMP version
  • D. profile

Answer: B

Explanation:
Reference:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_network_devices.html

 

NEW QUESTION 129
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.

Answer:

Explanation:

 

NEW QUESTION 130
Refer to the exhibit.
Which two configurations are needed on a catalyst switch for it to be added as a network access device in a Cisco ISE that is being used for 802 1X authentications? (Choose two )

  • A. Option E
  • B. Option B
  • C. Option C
  • D. Option D
  • E. Option A

Answer: C,E

 

NEW QUESTION 131
A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group.
Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?

  • A. Authenticate guest users to Cisco ISE
  • B. Configure authorization settings for guest users
  • C. Create and manage guest user accounts
  • D. Keep track of guest user activities

Answer: B

 

NEW QUESTION 132
A Cisco ISE administrator must restrict specific endpoints from accessing the network while in closed mode. The requirement is to have Cisco ISE centrally store the endpoints to restrict access from. What must be done to accomplish this task''

  • A. Create a profiling policy for each endpoint with the cdpCacheDeviceld attribute.
  • B. Add each IP address to a policy denying access.
  • C. Create a logical profile for each device's profile policy and block that via authorization policies.
  • D. Add each MAC address manually to a blocklist identity group and create a policy denying access

Answer: C

 

NEW QUESTION 133
What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?

  • A. MAB
  • B. posture
  • C. central web authentication
  • D. profiling

Answer: D

 

NEW QUESTION 134
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two )

  • A. administration
  • B. primary
  • C. subscriber
  • D. policy service
  • E. publisher

Answer: A,D

 

NEW QUESTION 135
Which protocol must be allowed for a BYOD device to access the BYOD portal?

  • A. SSH
  • B. HTTPS
  • C. SMTP
  • D. HTTP

Answer: B

Explanation:
Section: BYOD

 

NEW QUESTION 136
An engineer is configuring a guest password policy and needs to ensure that the password complexity requirements are set to mitigate brute force attacks. Which two requirement complete this policy? (Choose two)

  • A. access code control
  • B. username expiration date
  • C. active username limit
  • D. gpassword expiration period
  • E. minimum password length

Answer: D,E

 

NEW QUESTION 137
Drag the steps to configure a Cisco ISE node as a primary administration node from the left into the correct order on the night.

Answer:

Explanation:

 

NEW QUESTION 138
Which two default endpoint identity groups does Cisco ISE create? (Choose two )

  • A. allow list
  • B. profiled
  • C. unknown
  • D. endpoint
  • E. block list

Answer: B,C

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html Default Endpoint Identity Groups Created for Endpoints Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group. These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
Workstation-An identity group that contains all the profiled workstations on your network.

 

NEW QUESTION 139
Drag the descriptions on the left onto the components of 802.1X on the right.

Answer:

Explanation:

 

NEW QUESTION 140
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles? (Choose two.)

  • A. Firepower
  • B. ASA
  • C. WLC
  • D. Shell
  • E. IOS

Answer: C,D

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-
1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_0100010.html TACACS+ Profile TACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets. The TACACS+ profile definitions are split into two components:
Common tasks
Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)--Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
Shell
WLC
Nexus
Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.

 

NEW QUESTION 141
What are two requirements of generating a single signing in Cisco ISE by using a certificate provisioning portal, without generating a certificate request? (Choose two )

  • A. Choose the hashing method
  • B. Enter the common name
  • C. Location the CSV file for the device MAC
  • D. Select the certificate template
  • E. Enter the IP address of the device

Answer: B,D

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html

 

NEW QUESTION 142
An engineer is configuring 802.1X and wants it to be transparent from the users' point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices. Which deployment mode should be used to achieve this?

  • A. open
  • B. low-impact
  • C. high-impact
  • D. closed

Answer: A

 

NEW QUESTION 143
An engineer is configuring TACACS+ within Cisco ISE for use with a non-Cisco network device. They need to send special attributes in the Access-Accept response to ensure that the users are given the appropriate access. What must be configured to accomplish this'?

  • A. shell profiles with custom attributes that define the various roles
  • B. TACACS+ command sets to provide appropriate access
  • C. dACLs to enforce the various access policies for the users
  • D. custom access conditions for defining the different roles

Answer: A

 

NEW QUESTION 144
How is policy services node redundancy achieved in a deployment?

  • A. by deploying both primary and secondary node
  • B. by enabling VIP
  • C. by utilizing RADIUS server list on the NAD
  • D. by creating a node group

Answer: D

 

NEW QUESTION 145
What is the Cisco ISE default admin login name and password?

  • A. admin/no default password--the admin password is configured at setup
  • B. admin/admin
  • C. ISEAdmin/admin
  • D. admin/cisco

Answer: A

 

NEW QUESTION 146
When setting up profiling in an environment using Cisco ISE for network access control, an organization must use non-proprietary protocols for collecting the information at layer 2. Which two probes will provide this information without forwarding SPAN packets to Cisco ISE? {Choose two.)

  • A. NetFlow probe
  • B. DHCP SPAN probe
  • C. SNMP query probe
  • D. RADIUS probe
  • E. DNS probe

Answer: C,D

Explanation:
Reference:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design

 

NEW QUESTION 147
Which two external identity stores support EAP-TLS and PEAP-TLS? (Choose two.)

  • A. Active Directory
  • B. RSA SecurlD
  • C. Internal Database
  • D. LDAP
  • E. RADIUS Token

Answer: A,D

 

NEW QUESTION 148
An engineer is configuring web authentication using non-standard ports and needs the switch to redirect traffic to the correct port. Which command should be used to accomplish this task?

  • A. aaa group server radius proxy
  • B. aaa group server radius
  • C. ip http port <port number>
  • D. permit tcp any any eq <port number>

Answer: C

 

NEW QUESTION 149
......


Understanding functional and technical aspects of Implementing and Configuring Cisco Identity Services Engine (300-715 SISE) Network access device administration

The following will be discussed in CISCO 300-715 exam dumps:

  • Describe Cisco BYOD functionality
  • Use cases and requirements
  • Configure BYOD device on-boarding using internal CA with Cisco switches and Cisco wireless LAN controllers

 

Valid 300-715 Exam Dumps Ensure you a HIGH SCORE: https://interfacett.braindumpquiz.com/300-715-exam-material.html