New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions
Questions # 1:

An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?

Options:

A.

MDM


B.

Client provisioning


C.

My devices


D.

BYOD


Expert Solution
Questions # 2:

On which port does Cisco ISE present the Admin certificate for posture and client provisioning?

Options:

A.

TCP/8000


B.

TCP/8080


C.

TCP/8905


D.

TCP/8999


Expert Solution
Questions # 3:

An organization is migrating its current guest network to Cisco ISE and has 1000 guest users in the current database There are no resources to enter this information into the Cisco ISE database manually. What must be done to accomplish this task effciently?

Options:

A.

Use a CSV file to import the guest accounts


B.

Use SOL to link me existing database to Ctsco ISE


C.

Use a JSON fie to automate the migration of guest accounts


D.

Use an XML file to change the existing format to match that of Cisco ISE


Expert Solution
Questions # 4:

The security engineer for a company has recently deployed Cisco ISE to perform centralized authentication of all network device logins using TACACS+ against the local AD domain. Some of the other network engineers are having a hard time remembering to enter their AD account password instead of the local admin password that they have used for years. The security engineer wants to change the password prompt to "Use Local AD Password:" as a way of providing a hint to the network engineers when logging in. Under which page in Cisco ISE would this change be made?

Options:

A.

Work Centers > Device Administration > Settings > Connection Settings


B.

Work Centers > Device Administration > Ext Id Sources > Advanced Settings


C.

The password prompt cannot be changed on a Cisco IOS device


D.

Work Centers > Device Administration > Network Resources > Network Devices


Expert Solution
Questions # 5:

An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These configurations were performed:

• configured an identity group named allowlist

• configured the endpoints to use the MAC address of incompatible 802.1X devices

• added the endpoints to the allowlist identity group

• configured an authentication policy for MAB users

What must be configured?

Options:

A.

authorization profile that has the PermitAccess permission and matches the allowlist identity group


B.

logical profile that matches the allowlist identity group based on the configured policy


C.

authentication profile that has the PermitAccess permission and matches the allowlist identity group authorization policy that has the PermitAccess permission and matches the allowlist identity group


D.

authorization policy that has the PermitAccess permission and matches the allowtist identity group


Expert Solution
Questions # 6:

An engineer is configuring 802.1X and wants it to be transparent from the users' point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices. Which deployment mode should be used to achieve this?

Options:

A.

closed


B.

low-impact


C.

open


D.

high-impact


Expert Solution
Questions # 7:

What must match between Cisco ISE and the network access device to successfully authenticate endpoints?

Options:

A.

SNMP version


B.

shared secret


C.

certificate


D.

profile


Expert Solution
Questions # 8:

A network administrator must configure Cisco SE Personas in the company to share session information via syslog. Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?

Options:

A.

pxGrid


B.

admin


C.

policy services


D.

monitor


Expert Solution
Questions # 9:

An engineer is assigned to enhance security across the campus network. The task is to enable MAB across all access switches in the network. Which command must be entered on the switch to enable MAB?

Options:

A.

Switch(config-if)# mab


B.

Switch(config)# mab


C.

Switch# authentication port-control auto


D.

Switch(config)# authentication port-control auto


Expert Solution
Questions # 10:

Which command displays all 802 1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?

Options:

A.

show authentication sessions output


B.

Show authentication sessions


C.

show authentication sessions interface Gi 1/0/x


D.

show authentication sessions interface Gi1/0/x output


Expert Solution
Viewing page 1 out of 9 pages
Viewing questions 1-10 out of questions