Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions
Questions # 71:

The Cisco Wireless LAN Controller and guest portal must be set up in Cisco ISE. These configurations were performed:

• configured all the required Cisco Wireless LAN Controller configurations

• added the wireless controller to Cisco ISE network devices

• created an endpoint identity group

• configured credentials to be sent by email

• configured the SMTP server

• configured an authorization profile with redirection to the guest portal and redirected the access control list

• configured an authentication policy for MAB users

• created an authorization policy

Which two components would be required to complete the configuration? (Choose two.)

Options:

A.

sponsor group


B.

hotspot guest portal


C.

sponsor portal


D.

self-registered guest portal


E.

guest type


Expert Solution
Questions # 72:

Which CLI command must be configured on the switchport to immediately run the MAB process if a non-802.1X capable endpoint connects to the port?

Options:

A.

authentication order mab dot1x


B.

authentication fallback


C.

dot1x pae authenticator


D.

access-session port-control auto


Expert Solution
Questions # 73:

An administrator is configuring RADIUS on a Cisco switch with a key set to Cisc403012128 but is receiving the error “Authentication failed: 22040 Wrong password or invalid shared secret. “what must be done to address this issue?

Options:

A.

Add the network device as a NAD inside Cisco ISE using the existing key.


B.

Configure the key on the Cisco ISE instead of the Cisco switch.


C.

Use a key that is between eight and ten characters.


D.

Validate that the key is correct on both the Cisco switch as well as Cisco ISE.


Expert Solution
Questions # 74:

What is a difference between RADIUS versus TACACS+ with regards to packet encryption?

Options:

A.

TACACS+ encrypts the entire body of the packet, and RADIUS encrypts the username and password in the access-request packet.


B.

RADIUS encrypts the entire body of the packet, and TACACS+ encrypts the username and password in the access-request packet.


C.

RADIUS encrypts the entire body of the packet, and TACACS+ encrypts only the password in the access-request packet.


D.

TACACS+ encrypts the entire body of the packet, and RADIUS encrypts only the password in the access-request packet.


Expert Solution
Questions # 75:

What are two differences between the RADIUS and TACACS+ protocols'? (Choose two.)

Options:

A.

RADIUS is a Cisco proprietary protocol, whereas TACACS+ is an open standard protocol


B.

TACACS+uses TCP port 49. whereas RADIUS uses UDP ports 1812 and 1813.


C.

RADIUS offers multiprotocol support, whereas TACACS+ does not


D.

RADIUS combines authentication and authorization, whereas TACACS+ does not


E.

RADIUS enables encryption of all the packets, whereas with TACACS+. only the password is encrypted.


Expert Solution
Questions # 76:

Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?

(Choose two.)

Options:

A.

Firepower


B.

WLC


C.

IOS


D.

ASA


E.

Shell


Expert Solution
Questions # 77:

Select and Place


Expert Solution
Questions # 78:

Which portal is used to customize the settings for a user to log in and download the compliance module?

Options:

A.

Client Profiling


B.

Client Endpoint


C.

Client Provisioning


D.

Client Guest


Expert Solution
Questions # 79:

A network engineer must configure a centralized Cisco ISE solution for wireless guest access with users in different time zones. The guest account activation time must be independent of the user time zone, and the guest account must be enabled automatically when the user self-registers on the guest portal. Which option in the time profile settings must be selected to meet the requirement?

Options:

A.

Select FromFirstLogin from the Account Type dropdown.


B.

Select FromCreation from the Account Type dropdown.


C.

Set the Maximum Account Duration to 1 Day.


D.

Set the Duration field to 24:00:00.


Expert Solution
Questions # 80:

An administrator has added a new Cisco ISE PSN to their distributed deployment. Which two features must the administrator enable to accept authentication requests and profile the endpoints correctly, and add them to their respective endpoint identity groups? (Choose two )

Options:

A.

Session Services


B.

Endpoint Attribute Filter


C.

Posture Services


D.

Profiling Services


E.

Radius Service


Expert Solution
Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions