Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions
Questions # 41:

Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue. Which two requirements must be met to implement this change? (Choose two.)

Options:

A.

Enable IPC access over port 80.


B.

Ensure that the NAT address is properly configured


C.

Establish access to one Global Catalog server.


D.

Provide domain administrator access to Active Directory.


E.

Configure a secure LDAP connection.


Expert Solution
Questions # 42:

An engineer must deploy a WLAN that supports identity networking. The Cisco Wireless LAN Controller must be configured to apply the VLAN tag for client traffic returned by the RADIUS server. Which configuration parameter on the Cisco Wireless LAN Controller must be enabled to meet the requirement?

Options:

A.

Change of Authorization


B.

CWA Redirect ACL


C.

Allow AAA Override


D.

FlexConnect


Expert Solution
Questions # 43:

An administrator wants to configure network device administration and is trying to decide whether to use TACACS* or RADIUS. A reliable protocol must be used that can check command authorization Which protocol meets these requirements and why?

Options:

A.

TACACS+ because it runs over TCP


B.

RADIUS because it runs over UDP


C.

RADIUS because it runs over TCP.


D.

TACACS+ because it runs over UDP


Expert Solution
Questions # 44:

An administrator is configuring new probes to use with Cisco ISE and wants to use metadata to help profile the endpoints. The metadata must contain traffic information relating to the endpoints instead of industry-standard protocol information Which probe should be enabled to meet these requirements?

Options:

A.

NetFlow probe


B.

DNS probe


C.

DHCP probe


D.

SNMP query probe


Expert Solution
Questions # 45:

A network engineer must configure a centralized Cisco ISE solution for wireless guest access with users in different time zones. The guest account activation time must be independent of the user’s time zone, and the guest account must be enabled automatically when the user self-registers on the guest portal. Which option in the time profile settings must be selected to meet the requirement?

Options:

A.

Set the Minimum Account Duration to 10 days.


B.

Set the Duration Hours to 24:00.


C.

Select From Creation Date from the Account Type drop-down list.


D.

Select From First Login from the Account Type drop-down list.


Expert Solution
Questions # 46:

Using the SAK Active Directory Federation Services server. The configurations were performed:

• created a new SAML Identity provider profile in Cisco ISE

• exported the service provider Information

• configured all the required Active Directory Federation Services configurations

• Imported the Active Directory Federation Services metadata

• configured groups in the new SAML identity

• added attributes to the new SAML identity provider profile

• configured Advanced Settings in the new SAML identity provider profile

Which two actions must be taken to complete the configuration? (Choose two.)

Options:

A.

Allow Kerberos single sign-on on the Sponsor portal.


B.

Configure the Sponsor portal HTTPS port for Active Directory Federation Services integration.


C.

Customize the Sponsor portal pages for Integration with Active Directory Federation Services.


D.

Add SAML identity provider groups in Sponsor Group Members.


E.

Configure an identity source sequence in the Sponsor portal.


Expert Solution
Questions # 47:

An administrator connects an HP printer to a dot1x enable port, but the printer in not accessible Which feature must the administrator enable to access the printer?

Options:

A.

MAC authentication bypass


B.

change of authorization


C.

TACACS authentication


D.

RADIUS authentication


Expert Solution
Questions # 48:

Which permission is common to the Active Directory Join and Leave operations?

Options:

A.

Create a Cisco ISE machine account in the domain if the machine account does not already exist


B.

Remove the Cisco ISE machine account from the domain.


C.

Set attributes on the Cisco ISE machine account


D.

Search Active Directory to see if a Cisco ISE machine account already ex.sts.


Expert Solution
Questions # 49:

When planning for the deployment of Cisco ISE, an organization ' s security policy dictates that they must use network access authentication via RADIUS. It also states that the deployment provide an adequate amount of security and visibility for the hosts on the network. Why should the engineer configure MAB in this situation?

Options:

A.

The Cisco switches only support MAB.


B.

MAB provides the strongest form of authentication available.


C.

The devices in the network do not have a supplicant.


D.

MAB provides user authentication.


Expert Solution
Questions # 50:

What is the difference between how RADIUS and TACACS+ handle encryption?

Options:

A.

RADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields.


B.

RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.


C.

RADIUS only encrypts the password field, whereas TACACS+ encrypts the payload of the packet.


D.

RADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet.


Expert Solution
Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions