Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions
Questions # 11:

An administrator is configuring sponsored guest access using Cisco ISE Access must be restricted to the sponsor portal to ensure that only necessary employees can issue sponsored accounts and employees must be classified to do so What must be done to accomplish this task?

Options:

A.

Configure an identity-based access list in Cisco ISE to restrict the users allowed to login


B.

Edit the sponsor portal to only accept members from the selected groups


C.

Modify the sponsor groups assigned to reflect the desired user groups


D.

Create an authorization rule using the Guest Flow condition to authorize the administrators


Expert Solution
Questions # 12:

Question # 12

Refer to the exhibit Which component must be configured to apply the SGACL?

Options:

A.

egress router


B.

host


C.

secure server


D.

ingress router


Expert Solution
Questions # 13:

An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.


Expert Solution
Questions # 14:

An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node. Which persona should be configured with the largest amount of storage in this environment?

Options:

A.

policy Services


B.

Primary Administration


C.

Monitoring and Troubleshooting


D.

Platform Exchange Grid


Expert Solution
Questions # 15:

Which two values are compared by the binary comparison (unction in authentication that is based on Active Directory?

Options:

A.

subject alternative name and the common name


B.

MS-CHAPv2 provided machine credentials and credentials stored in Active Directory


C.

user-presented password hash and a hash stored in Active Directory


D.

user-presented certificate and a certificate stored in Active Directory


Expert Solution
Questions # 16:

What allows an endpoint to obtain a digital certificate from Cisco ISE during a BYOD flow?

Options:

A.

Network Access Control


B.

My Devices Portal


C.

Application Visibility and Control


D.

Supplicant Provisioning Wizard


Expert Solution
Questions # 17:

A network engineer is configuring guest access and notices that when a guest user registers a second device for access, the first device loses access What must be done to ensure that both devices for a particular user are able to access the guest network simultaneously?

Options:

A.

Configure the sponsor group to increase the number of logins.


B.

Use a custom portal to increase the number of logins


C.

Modify the guest type to increase the number of maximum devices


D.

Create an Adaptive Network Control policy to increase the number of devices


Expert Solution
Questions # 18:

Which use case validates a change of authorization?

Options:

A.

An authenticated, wired EAP-capable endpoint is discovered


B.

An endpoint profiling policy is changed for authorization policy.


C.

An endpoint that is disconnected from the network is discovered


D.

Endpoints are created through device registration for the guests


Expert Solution
Questions # 19:

Question # 19

Refer to the exhibit. In which scenario does this switch configuration apply?

Options:

A.

when allowing a hub with multiple clients connected


B.

when passing IP phone authentication


C.

when allowing multiple IP phones to be connected


D.

when preventing users with hypervisor


Expert Solution
Questions # 20:

Which two probes must be enabled for the ARP cache to function in the Cisco ISE profile service so that a user can reliably bind the IP address and MAC addresses of endpoints? (Choose two.)

Options:

A.

NetFlow


B.

SNMP


C.

HTTP


D.

DHCP


E.

RADIUS


Expert Solution
Viewing page 2 out of 9 pages
Viewing questions 11-20 out of questions