New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions
Questions # 41:

What gives Cisco ISE an option to scan endpoints for vulnerabilities?

Options:

A.

authorization policy


B.

authentication policy


C.

authentication profile


D.

authorization profile


Expert Solution
Questions # 42:

An engineer is unable to use SSH to connect to a switch after adding the required CLI commands to the device to enable TACACS+. The device administration license has been added to Cisco ISE, and the required policies have been created. Which action is needed to enable access to the switch?

Options:

A.

The ip ssh source-interface command needs to be set on the switch


B.

802.1X authentication needs to be configured on the switch.


C.

The RSA keypair used for SSH must be regenerated after enabling TACACS+.


D.

The switch needs to be added as a network device in Cisco ISE and set to use TACACS+.


Expert Solution
Questions # 43:

An administrator is attempting to join a new node to the primary Cisco ISE node, but receives the error message "Node is Unreachable". What is causing this error?

Options:

A.

The second node is a PAN node.


B.

No administrative certificate is available for the second node.


C.

The second node is in standalone mode.


D.

No admin privileges are available on the second node.


Expert Solution
Questions # 44:

What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?

Options:

A.

a primary and secondary PAN and a health check node for the Secondary PAN


B.

a primary and secondary PAN and no health check nodes


C.

a primary and secondary PAN and a pair of health check nodes


D.

a primary and secondary PAN and a health check node for the Primary PAN


Expert Solution
Questions # 45:

There are several devices on a network that are considered critical and need to be placed into the ISE database and a policy used for them. The organization does not want to use profiling. What must be done to accomplish this goal?

Options:

A.

Enter the MAC address in the correct Endpoint Identity Group.


B.

Enter the MAC address in the correct Logical Profile.


C.

Enter the IP address in the correct Logical Profile.


D.

Enter the IP address in the correct Endpoint Identity Group.


Expert Solution
Questions # 46:

What does a fully distributed Cisco ISE deployment include?

Options:

A.

PAN and PSN on the same node while MnTs are on their own dedicated nodes.


B.

PAN and MnT on the same node while PSNs are on their own dedicated nodes.


C.

All Cisco ISE personas on their own dedicated nodes.


D.

All Cisco ISE personas are sharing the same node.


Expert Solution
Questions # 47:

An engineer needs to configure Cisco ISE Profiling Services to authorize network access for IP speakers that require access to the intercom system. This traffic needs to be identified if the ToS bit is set to 5 and the destination IP address is the intercom system. What must be configured to accomplish this goal?

Options:

A.

NMAP


B.

NETFLOW


C.

pxGrid


D.

RADIUS


Expert Solution
Questions # 48:

If a user reports a device lost or stolen, which portal should be used to prevent the device from accessing the network while still providing information about why the device is blocked?

Options:

A.

Client Provisioning


B.

Guest


C.

BYOD


D.

Blacklist


Expert Solution
Questions # 49:

A company is attempting to improve their BYOD policies and restrict access based on certain criteria. The company's subnets are organized by building. Which attribute should be used in order to gain access based on location?

Options:

A.

static group assignment


B.

IP address


C.

device registration status


D.

MAC address


Expert Solution
Questions # 50:

Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two.)

Options:

A.

hotspot


B.

new AD user 802 1X authentication


C.

posture


D.

BYOD


E.

guest AUP


Expert Solution
Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions