Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions
Questions # 11:

An engineer is creating a new authorization policy to give the endpoints access to VLAN 310 upon successful authentication The administrator tests the 802.1X authentication for the endpoint and sees that it is authenticating successfully What must be done to ensure that the endpoint is placed into the correct VLAN?

Options:

A.

Configure the switchport access vlan 310 command on the switch port


B.

Ensure that the security group is not preventing the endpoint from being in VLAN 310


C.

Add VLAN 310 in the common tasks of the authorization profile


D.

Ensure that the endpoint is using The correct policy set


Expert Solution
Questions # 12:

An engineer must configure guest access on Cisco ISE for company visitors. Which step must be taken on the Cisco ISE PSNs before a guest portal is configured?

Options:

A.

Enable profiling services.


B.

Install SSL certificates.


C.

Create a node group.


D.

Enable session services.


Expert Solution
Questions # 13:

A company is attempting to improve their BYOD policies and restrict access based on certain criteria. The company ' s subnets are organized by building. Which attribute should be used in order to gain access based on location?

Options:

A.

static group assignment


B.

IP address


C.

device registration status


D.

MAC address


Expert Solution
Questions # 14:

Which two ports do network devices typically use for CoA? (Choose two)

Options:

A.

443


B.

19005


C.

8080


D.

3799


E.

1700


Expert Solution
Questions # 15:

An engineer needs to configure Cisco ISE Profiling Services to authorize network access for IP speakers that require access to the intercom system. This traffic needs to be identified if the ToS bit is set to 5 and the destination IP address is the intercom system. What must be configured to accomplish this goal?

Options:

A.

NMAP


B.

NETFLOW


C.

pxGrid


D.

RADIUS


Expert Solution
Questions # 16:

An administrator must deploy the Cisco Secure Client posture agent to employee endpoints that access a wireless network by using URL redirection in Cisco ISE. The compliance module must be downloaded from Cisco and uploaded to the Cisco ISE client provisioning resource. What must be used to upload the compliance module?

Options:

A.

Secure Client configuration


B.

agent resources from the local disk


C.

Secure Client posture profile


D.

Client Provisioning Portal


Expert Solution
Questions # 17:

A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

Options:

A.

Port Bounce


B.

Reauth


C.

NoCoA


D.

Disconnect


Expert Solution
Questions # 18:

An administrator must authenticate Cisco Secure Client users by using a secure token against an LDAP server to grant wireless network access in a Cisco ISE deployment. These configurations have been performed:

• Configured Microsoft Active Directory as an external identity source

• Created an authentication policy

• Created an authorization policy

The administrator must create a Cisco Secure Client profile to complete the configuration. Which protocol must be implemented in the policy?

Options:

A.

LEAP


B.

EAP-GTC


C.

MS-CHAPv2


D.

EAP-MD5


Expert Solution
Questions # 19:

Question # 19

Refer to the exhibit. An engineer must configure BYOD in Cisco ISE. A single SSID must be used to allow BYOD devices to connect to the network. These configurations have been performed on Wireless LAN Controller already:

RADIUS server

BYOD-Dot1x SSID

Which two configurations must be done in Cisco ISE to meet the requirement? (Choose two.)

Options:

A.

FlexConnect ACL


B.

External identity source


C.

Authentication policy


D.

Redirect ACL


E.

Profiling policy


Expert Solution
Questions # 20:

If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

Options:

A.

Client Provisioning


B.

Guest


C.

BYOD


D.

Blacklist


Expert Solution
Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions