Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which type of identity store allows for creating single-use access credentials in Cisco ISE?

Options:

A.

OpenLDAP


B.

Local


C.

PKI


D.

RSA SecurID


Expert Solution
Questions # 12:

An organization is adding new profiling probes to the system to improve profiling on Oseo ISE The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected What must be configured on the network device to accomplish this goal?

Options:

A.

ARP


B.

SNMP


C.

WCCP


D.

ICMP


Expert Solution
Questions # 13:

Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two.)

Options:

A.

hotspot


B.

new AD user 802 1X authentication


C.

posture


D.

BYOD


E.

guest AUP


Expert Solution
Questions # 14:

An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out Which configuration is causing this behavior?

Options:

A.

One of the nodes is an active PSN.


B.

One of the nodes is the Primary PAN


C.

All of the nodes participate in the PAN auto failover.


D.

All of the nodes are actively being synched.


Expert Solution
Questions # 15:

What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?

Options:

A.

a primary and secondary PAN and a health check node for the Secondary PAN


B.

a primary and secondary PAN and no health check nodes


C.

a primary and secondary PAN and a pair of health check nodes


D.

a primary and secondary PAN and a health check node for the Primary PAN


Expert Solution
Questions # 16:

An organization is hosting a conference and must make guest accounts for several of the speakers attending. The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?

Options:

A.

Create an authorization rule denying sponsored guest access.


B.

Navigate to the Guest Portal and delete the guest accounts.


C.

Create an authorization rule denying guest access.


D.

Navigate to the Sponsor Portal and suspend the guest accounts.


Expert Solution
Questions # 17:

An engineer needs to configure a Cisco ISE server to issue a CoA for endpoints already authenticated to access the network. The CoA option must be enforced on a session, even if there are multiple active sessions on a port. What must be configured to accomplish this task?

Options:

A.

the Reauth CoA option in the Cisco ISE system profiling settings enabled


B.

an endpoint profiling policy with the No CoA option enabled


C.

an endpoint profiling policy with the Port Bounce CoA option enabled


D.

the Port Bounce CoA option in the Cisco ISE system profiling settings enabled


Expert Solution
Questions # 18:

An administrator wants to configure network device administration and is trying to decide whether to use TACACS* or RADIUS. A reliable protocol must be used that can check command authorization Which protocol meets these requirements and why?

Options:

A.

TACACS+ because it runs over TCP


B.

RADIUS because it runs over UDP


C.

RADIUS because it runs over TCP.


D.

TACACS+ because it runs over UDP


Expert Solution
Questions # 19:

An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?

Options:

A.

ip source guard


B.

ip dhcp snooping


C.

ip device tracking maximum


D.

ip arp inspection


Expert Solution
Questions # 20:

Select and Place

Question # 20


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions