Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions
Questions # 61:

A network administrator adds network access devices to Cisco ISE. After a security breach, the management team mandates that all network devices must comply with certain standards. All network devices must authenticate through Cisco ISE. Some devices use nondefault CoA ports.

What must be configured in Cisco ISE?

Options:

A.

Network device profile with a port specified


B.

Network access manager with a port specified


C.

Network device group with a port specified


D.

Network device with a port specified


Expert Solution
Questions # 62:

A network engineer is in the predeployment discovery phase of a Cisco ISE deployment and must discover the network. There is an existing network management system in the network.

Which type of probe must be configured to gather the information?

Options:

A.

RADIUS


B.

NMAP


C.

NetFlow


D.

SNMP


Expert Solution
Questions # 63:

Which two default guest portals are available with Cisco ISE? (Choose two.)

Options:

A.

visitor


B.

WIFI-access


C.

self-registered


D.

central web authentication


E.

sponsored


Expert Solution
Questions # 64:

An engineer is configuring a dedicated SSID for onboarding devices. Which SSID type accomplishes this configuration?

Options:

A.

dual


B.

hidden


C.

broadcast


D.

guest


Expert Solution
Questions # 65:

An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

Options:

A.

VLAN to SGT mapping


B.

IP Address to SGT mapping


C.

L3IF to SGT mapping


D.

Subnet to SGT mapping


Expert Solution
Questions # 66:

An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?

Options:

A.

authentication open


B.

pae dot1x enabled


C.

authentication host-mode multi-auth


D.

monitor-mode enabled


Expert Solution
Questions # 67:

An engineer is creating a new authorization policy to give the endpoints access to VLAN 310 upon successful authentication The administrator tests the 802.1X authentication for the endpoint and sees that it is authenticating successfully What must be done to ensure that the endpoint is placed into the correct VLAN?

Options:

A.

Configure the switchport access vlan 310 command on the switch port


B.

Ensure that the security group is not preventing the endpoint from being in VLAN 310


C.

Add VLAN 310 in the common tasks of the authorization profile


D.

Ensure that the endpoint is using The correct policy set


Expert Solution
Questions # 68:

A network administrator is configuring authorization policies on Cisco ISE There is a requirement to use AD group assignments to control access to network resources After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work What is the cause of this issue?

Options:

A.

The AD join point is no longer connected.


B.

The AD DNS response is slow.


C.

The certificate checks are not being conducted.


D.

The network devices ports are shut down.


Expert Solution
Questions # 69:

What are two components of the posture requirement when configuring Cisco ISE posture? (Choose two)

Options:

A.

updates


B.

remediation actions


C.

Client Provisioning portal


D.

conditions


E.

access policy


Expert Solution
Questions # 70:

A network administrator is configuring a secondary cisco ISE node from the backup configuration of the primary cisco ISE node to create a high availability pair The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE Which command most be issued for this to work?

Options:

A.

copy certificate Ise


B.

application configure Ise


C.

certificate configure Ise


D.

Import certificate Ise


Expert Solution
Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions