Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions
Questions # 41:

Which advanced option within a WLAN must be enabled to trigger Central Web Authentication for Wireless users on AireOS controller?

Options:

A.

DHCP server


B.

static IP tunneling


C.

override Interface ACL


D.

AAA override


Expert Solution
Questions # 42:

Which nodes are supported in a distributed Cisco ISE deployment?

Options:

A.

Policy Service nodes for session failover


B.

Monitoring nodes for PxGrid services


C.

Administration nodes for session failover


D.

Policy Service nodes for automatic failover


Expert Solution
Questions # 43:

An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These configurations were performed:

    Configured an identity group named allowlist

    Configured the endpoints to use the MAC address of incompatible 802.1X devices

    Added the endpoints to the allowlist identity group

    Configured an authentication policy for MAB users

What must be configured?

Options:

A.

Authorization profile that has the PermitAccess permission and matches the allowlist identity group


B.

Authentication profile that has the PermitAccess permission and matches the allowlist identity group


C.

Authorization policy that has the PermitAccess permission and matches the allowlist identity group


D.

Logical profile that matches the allowlist identity group based on the configured policy


Expert Solution
Questions # 44:

Which two default endpoint identity groups does Cisco ISE create? (Choose two )

Options:

A.

block list


B.

endpoint


C.

profiled


D.

allow list


E.

unknown


Expert Solution
Questions # 45:

Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?

Options:

A.

EAP server


B.

supplicant


C.

client


D.

authenticator


Expert Solution
Questions # 46:

An administrator enables the profiling service for Cisco ISE to use for authorization policies while in closed mode. When the endpoints connect, they receive limited access so that the profiling probes can gather information and Cisco ISE can assign the correct profiles. They are using the default values within Cisco ISE. but the devices do not change their access due to the new profile. What is the problem'?

Options:

A.

In closed mode, profiling does not work unless CDP is enabled.


B.

The profiling probes are not able to collect enough information to change the device profile


C.

The profiler feed is not downloading new information so the profiler is inactive


D.

The default profiler configuration is set to No CoA for the reauthentication setting


Expert Solution
Questions # 47:

An engineer is unable to use SSH to connect to a switch after adding the required CLI commands to the device to enable TACACS+. The device administration license has been added to Cisco ISE, and the required policies have been created. Which action is needed to enable access to the switch?

Options:

A.

The ip ssh source-interface command needs to be set on the switch


B.

802.1X authentication needs to be configured on the switch.


C.

The RSA keypair used for SSH must be regenerated after enabling TACACS+.


D.

The switch needs to be added as a network device in Cisco ISE and set to use TACACS+.


Expert Solution
Questions # 48:

A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

Options:

A.

Port Bounce


B.

Reauth


C.

NoCoA


D.

Disconnect


Expert Solution
Questions # 49:

Which command displays all 802 1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?

Options:

A.

show authentication sessions output


B.

Show authentication sessions


C.

show authentication sessions interface Gi 1/0/x


D.

show authentication sessions interface Gi1/0/x output


Expert Solution
Questions # 50:

A company manager is hosting a conference. Conference participants must connect to an open guest SSID and only use a preassigned code that they enter into the guest portal prior to gaining access to the network. How should the manager configure Cisco ISE to accomplish this goal?

Options:

A.

Create entries in the guest identity group for all participants.


B.

Create an access code to be entered in the AUP page.


C.

Create logins for each participant to give them sponsored access.


D.

Create a registration code to be entered on the portal splash page.


Expert Solution
Viewing page 5 out of 9 pages
Viewing questions 41-50 out of questions