New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions
Questions # 51:

An administrator connects an HP printer to a dot1x enable port, but the printer in not accessible Which feature must the administrator enable to access the printer?

Options:

A.

MAC authentication bypass


B.

change of authorization


C.

TACACS authentication


D.

RADIUS authentication


Expert Solution
Questions # 52:

Which two events trigger a CoA for an endpoint when CoA is enabled globally for ReAuth? (Choose two.)

Options:

A.

endpoint marked as lost in My Devices Portal


B.

addition of endpoint to My Devices Portal


C.

endpoint profile transition from Apple-Device to Apple-iPhone


D.

endpoint profile transition from Unknown to Windows 10-Workstation


E.

updating of endpoint dACL.


Expert Solution
Questions # 53:

TION NO: 33

Which portal is used to customize the settings for a user to log in and download the compliance module?

Options:

A.

Client Profiling


B.

Client Endpoint


C.

Client Provisioning


D.

Client Guest


Expert Solution
Questions # 54:

When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?

Options:

A.

MIB


B.

TGT


C.

OMAB


D.

SID


Expert Solution
Questions # 55:

An engineer is deploying a new Cisco ISE environment for a company. The company wants the deployment to use TACACS+. The engineer verifies that Cisco ISE has a Device Administration license. What must be configured to enable TACACS+ operations?

Options:

A.

Device Administration Work Center


B.

Device Admin service


C.

Device Administration Deployment settings


D.

Device Admin Policy Sets settings


Expert Solution
Questions # 56:

An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?

Options:

A.

HTTP probe


B.

NetFlow probe


C.

network scan probe


D.

RADIUS probe


Expert Solution
Questions # 57:

What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?

Options:

A.

The primary node restarts


B.

The secondary node restarts.


C.

The primary node becomes standalone


D.

Both nodes restart.


Expert Solution
Questions # 58:

Which two features must be used on Cisco ISE to enable the TACACS. feature? (Choose two)

Options:

A.

Device Administration License


B.

Server Sequence


C.

Command Sets


D.

Enable Device Admin Service


E.

External TACACS Servers


Expert Solution
Questions # 59:

An engineer is configuring Cisco ISE policies to support MAB for devices that do not have 802.1X capabilities. The engineer is configuring new endpoint identity groups as conditions to be used in the AuthZ policies, but noticed that the endpoints are not hitting the correct policies. What must be done in order to get the devices into the right policies?

Options:

A.

Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.


B.

Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.


C.

Add an identity policy to dynamically add the IP address of the devices to their endpoint identity groups.


D.

Identify the non 802.1X supported device types and create custom profiles for them to profile into.


Expert Solution
Questions # 60:

What is a difference between RADIUS versus TACACS+ with regards to packet encryption?

Options:

A.

TACACS+ encrypts the entire body of the packet, and RADIUS encrypts the username and password in the access-request packet.


B.

RADIUS encrypts the entire body of the packet, and TACACS+ encrypts the username and password in the access-request packet.


C.

RADIUS encrypts the entire body of the packet, and TACACS+ encrypts only the password in the access-request packet.


D.

TACACS+ encrypts the entire body of the packet, and RADIUS encrypts only the password in the access-request packet.


Expert Solution
Viewing page 6 out of 9 pages
Viewing questions 51-60 out of questions