Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions
Questions # 1:

What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?

Options:

A.

Cisco-av-pair


B.

Class attribute


C.

Event


D.

State attribute


Expert Solution
Questions # 2:

In a Cisco ISE split deployment model, which load is split between the nodes?

Options:

A.

AAA


B.

network admission


C.

log collection


D.

device admission


Expert Solution
Questions # 3:

Which two default endpoint identity groups does Cisco ISE create? (Choose two )

Options:

A.

block list


B.

endpoint


C.

profiled


D.

allow list


E.

unknown


Expert Solution
Questions # 4:

An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. From which Cisco ISE persona should this traffic be originating?

Options:

A.

monitoring


B.

policy service


C.

administration


D.

authentication


Expert Solution
Questions # 5:

In which two ways can users and endpoints be classified for TrustSec?

(Choose Two.)

Options:

A.

VLAN


B.

SXP


C.

dynamic


D.

QoS


E.

SGACL


Expert Solution
Questions # 6:

Refer to the exhibit. An engineer is creating a new TACACS* command set and cannot use any show commands after togging into the device with this command set authorization Which configuration is causing this issue?

Options:

A.

Question marks are not allowed as wildcards for command sets.


B.

The command set is allowing all commands that are not in the command list


C.

The wildcard command listed is in the wrong format


D.

The command set is working like an ACL and denying every command.


Expert Solution
Questions # 7:

Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?

Options:

A.

session timeout


B.

idle timeout


C.

radius-server timeout


D.

termination-action


Expert Solution
Questions # 8:

What is the maximum number of PSN nodes supported in a medium-sized deployment?

Options:

A.

three


B.

five


C.

two


D.

eight


Expert Solution
Questions # 9:

Question # 9

Refer to the exhibit Which component must be configured to apply the SGACL?

Options:

A.

egress router


B.

host


C.

secure server


D.

ingress router


Expert Solution
Questions # 10:

When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen What is causing this issue?

Options:

A.

Cisco ISE only sees the built-in groups, not user created ones


B.

The groups are present but need to be manually typed as conditions


C.

Cisco ISE's connection to the AD join point is failing


D.

The groups are not added to Cisco ISE under the AD join point


Expert Solution
Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions