Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions
Questions # 51:

An administrator made changes in Cisco ISE and needs to apply new permissions for endpoints that have already been authenticated by sending a CoA packet to the network devices. Which IOS command must be configured on the devices to accomplish this goal?

Options:

A.

aaa server radius dynamic-author


B.

authentication command bounce-port


C.

authentication command disable-port


D.

aaa nas port extended


Expert Solution
Questions # 52:

An engineer is configuring ISE for network device administration and has devices that support both protocols. What are two benefits of choosing TACACS+ over RADUs for these devices? (Choose two.)

Options:

A.

TACACS+ is FIPS compliant while RADIUS is not


B.

TACACS+ is designed for network access control while RADIUS is designed for role-based access.


C.

TACACS+ uses secure EAP-TLS while RADIUS does not.


D.

TACACS+ provides the ability to authorize specific commands while RADIUS does not


E.

TACACS+ encrypts the entire payload being sent while RADIUS only encrypts the password.


Expert Solution
Questions # 53:

An engineer is assigned to enhance security across the campus network. The task is to enable MAB across all access switches in the network. Which command must be entered on the switch to enable MAB?

Options:

A.

Switch(config-if)# mab


B.

Switch(config)# mab


C.

Switch# authentication port-control auto


D.

Switch(config)# authentication port-control auto


Expert Solution
Questions # 54:

Which supplicant(s) and server(s) are capable of supporting EAP-CHAINING?

Options:

A.

Cisco AnyConnect NAM and Cisco Identity Service Engine


B.

Cisco AnyConnect NAM and Cisco Access Control Server


C.

Cisco Secure Services Client and Cisco Access Control Server


D.

Windows Native Supplicant and Cisco Identity Service Engine


Expert Solution
Questions # 55:

An engineer is starting to implement a wired 802.1X project throughout the campus. The task is to ensure that the authentication procedure is disabled on the ports but still allows all endpoints to connect to the network. Which port-control option must the engineer configure?

Options:

A.

pae-disabled


B.

force-unauthorized


C.

auto


D.

force-authorized


Expert Solution
Questions # 56:

A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?

Options:

A.

The AD join point is no longer connected.


B.

The AD DNS response is slow.


C.

The certificate checks are not being conducted.


D.

The network devices ports are shut down.


Expert Solution
Questions # 57:

An adminístrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs. Besides defining a new shell profile in Cisco ISE. what must be done to accomplish this configuration?

Options:

A.

Enable the privilege levels in Cisco ISE


B.

B. Enable the privilege levels in the IOS devices.


C.

Define the command privileges for levels 2-5 in the IOS devices


D.

Define the command privileges for levels 2-5 in Cisco ISE


Expert Solution
Questions # 58:

Which action must be taken before configuring the Secure Client Agent profile when creating the Secure Client configuration for ISE posture services?

Options:

A.

Create a posture remediation condition policy for the Agent profile.


B.

Configure the posture policy for Secure Client posturing module.


C.

Create a posture condition that references the Secure Client package.


D.

Upload the Secure Client packages and the Secure Client compliance modules.


Expert Solution
Questions # 59:

Which RADIUS attribute is used to dynamically assign the inactivity active timer for MAB users from the Cisco ISE node ' ?

Options:

A.

radius-server timeout


B.

session-timeout


C.

idle-timeout


D.

termination-action


Expert Solution
Questions # 60:

An administrator is responsible for configuring network access for a temporary network printer. The administrator must only use the printer MAC address 50:89:65: 18:8: AB for authentication. Which authentication method will accomplish the task?

Options:

A.

Posturing


B.

Profiling


C.

MAB


D.

802.1x


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions