Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

What is a restriction of a standalone Cisco ISE node deployment?

Options:

A.

Only the Policy Service persona can be disabled on the node.


B.

The domain name of the node cannot be changed after installation.


C.

Personas are enabled by default and cannot be edited on the node.


D.

The hostname of the node cannot be changed after installation.


Expert Solution
Questions # 42:

Which two default guest portals are available with Cisco ISE? (Choose two.)

Options:

A.

visitor


B.

WIFI-access


C.

self-registered


D.

central web authentication


E.

sponsored


Expert Solution
Questions # 43:

A network engineer is configuring guest access and notices that when a guest user registers a second device for access, the first device loses access What must be done to ensure that both devices for a particular user are able to access the guest network simultaneously?

Options:

A.

Configure the sponsor group to increase the number of logins.


B.

Use a custom portal to increase the number of logins


C.

Modify the guest type to increase the number of maximum devices


D.

Create an Adaptive Network Control policy to increase the number of devices


Expert Solution
Questions # 44:

A customer wants to set up the Sponsor portal and delegate the authentication flow to a third party for added security while using Kerberos Which database should be used to accomplish this goal?

Options:

A.

RSA Token Server


B.

Active Directory


C.

Local Database


D.

LDAP


Expert Solution
Questions # 45:

A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

Options:

A.

Port Bounce


B.

Reauth


C.

NoCoA


D.

Disconnect


Expert Solution
Questions # 46:

A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for one day When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?

Options:

A.

The Endpoint Purge Policy is set to 30 days for guest devices


B.

The RADIUS policy set for guest access is set to allow repeated authentication of the same device


C.

The length of access is set to 7 days in the Guest Portal Settings


D.

The Guest Account Purge Policy is set to 15 days


Expert Solution
Questions # 47:

An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE. What must be configured within Cisco ISE to accomplish this goal?

Options:

A.

Create a certificate signing request and have the root certificate authority sign it.


B.

Add the root certificate authority to the trust store and enable it for authentication.


C.

Create an SCEP profile to link Cisco ISE with the root certificate authority.


D.

Add an OCSP profile and configure the root certificate authority as secondary.


Expert Solution
Questions # 48:

When planning for the deployment of Cisco ISE, an organization's security policy dictates that they must use network access authentication via RADIUS. It also states that the deployment provide an adequate amount of security and visibility for the hosts on the network. Why should the engineer configure MAB in this situation?

Options:

A.

The Cisco switches only support MAB.


B.

MAB provides the strongest form of authentication available.


C.

The devices in the network do not have a supplicant.


D.

MAB provides user authentication.


Expert Solution
Questions # 49:

An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?

Options:

A.

Use a third-party certificate on the network device.


B.

Add the device to all PSN nodes in the deployment.


C.

Renew the expired certificate on one of the PSN.


D.

Configure an authorization profile for the end users.


Expert Solution
Questions # 50:

An administrator needs to connect ISE to Active Directory as an external authentication source and allow the proper ports through the firewall. Which two ports should be opened to accomplish this task? (Choose two)

Options:

A.

TELNET 23


B.

LDAP 389


C.

HTTP 80


D.

HTTPS 443


E.

MSRPC 445


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions