Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions
Questions # 21:

Wireless network users authenticate to Cisco ISE using 802.1X through a Cisco Catalyst switch. An engineer must create an updated configuration to assign a security group tag to the user ' s traffic using inline tagging to prevent unauthenticated users from accessing a restricted server. The configurations were performed:

• configured Cisco ISE as a Cisco TrustSec AAA server

• configured the switch as a RADIUS device in Cisco ISE

• configured the wireless LAN controller as a TrustSec device in Cisco ISE

• created a security group tog for the wireless users

• created a certificate authentication profile

■ created an identity source sequence

• assigned an appropriate security group tag to the wireless users

• defined security group access control lists to specify an egress policy

• enforced the access control lists on the TrustSec policy matrix in Cisco ISE

• configured TrustSec on the switch

• configured TrustSec on the wireless LAN controller

Which two actions must be taken to complete the configuration? (Choose two.)

Options:

A.

Configure Security Group Tag Exchange Protocol on the wireless LAN controller.


B.

Configure Security Group Tag Exchange Protocol to distribute IP to security group tags on Cisco ISE.


C.

Configure inline tag propagation on the switch and wireless LAN controller.


D.

Create static IP-to-SGT mapping for the restricted web server.


E.

Configure Security Group Tag Exchange Protocol on the switch.


Expert Solution
Questions # 22:

A network administrator adds network access devices to Cisco ISE. After a security breach, the management team mandates that all network devices must comply with certain standards. All network devices must authenticate through Cisco ISE. Some devices use nondefault CoA ports.

What must be configured in Cisco ISE?

Options:

A.

Network device profile with a port specified


B.

Network access manager with a port specified


C.

Network device group with a port specified


D.

Network device with a port specified


Expert Solution
Questions # 23:

What is a restriction of a standalone Cisco ISE node deployment?

Options:

A.

Only the Policy Service persona can be disabled on the node.


B.

The domain name of the node cannot be changed after installation.


C.

Personas are enabled by default and cannot be edited on the node.


D.

The hostname of the node cannot be changed after installation.


Expert Solution
Questions # 24:

Which Cisco ISE deployment model provides redundancy by having every node in the deployment configured with the Administration. Policy Service, and Monitoring personas to protect from a complete node failure?

Options:

A.

distributed


B.

dispersed


C.

two-node


D.

hybrid


Expert Solution
Questions # 25:

An engineer is configuring Cisco ISE policies to support MAB for devices that do not have 802.1X capabilities. The engineer is configuring new endpoint identity groups as conditions to be used in the AuthZ policies, but noticed that the endpoints are not hitting the correct policies. What must be done in order to get the devices into the right policies?

Options:

A.

Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.


B.

Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.


C.

Add an identity policy to dynamically add the IP address of the devices to their endpoint identity groups.


D.

Identify the non 802.1X supported device types and create custom profiles for them to profile into.


Expert Solution
Questions # 26:

A customer wants to set up the Sponsor portal and delegate the authentication flow to a third party for added security while using Kerberos Which database should be used to accomplish this goal?

Options:

A.

RSA Token Server


B.

Active Directory


C.

Local Database


D.

LDAP


Expert Solution
Questions # 27:

TION NO: 33

Which portal is used to customize the settings for a user to log in and download the compliance module?

Options:

A.

Client Profiling


B.

Client Endpoint


C.

Client Provisioning


D.

Client Guest


Expert Solution
Questions # 28:

An engineer is configuring web authentication and needs to allow specific protocols to permit DNS traffic. Which type of access list should be used for this configuration?

Options:

A.

reflexive ACL


B.

extended ACL


C.

standard ACL


D.

numbered ACL


Expert Solution
Questions # 29:

An administrator is troubleshooting an endpoint that is supposed to bypass 802 1X and use MAB. The endpoint is bypassing 802.1X and successfully getting network access using MAB. however the endpoint cannot communicate because it cannot obtain an IP address. What is the problem?

Options:

A.

The DHCP probe for Cisco ISE is not working as expected.


B.

The 802.1 X timeout period is too long.


C.

The endpoint is using the wrong protocol to authenticate with Cisco ISE.


D.

An AC I on the port is blocking HTTP traffic


Expert Solution
Questions # 30:

An administrator is configuring a switch port for use with 802 1X What must be done so that the port will allow voice and multiple data endpoints?

Options:

A.

Configure the port with the authentication host-mode multi-auth command


B.

Connect the data devices to the port, then attach the phone behind them.


C.

Use the command authentication host-mode multi-domain on the port


D.

Connect a hub to the switch port to allow multiple devices access after authentication


Expert Solution
Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions