ExamGecko
Home Home / Cisco / 300-715

Cisco 300-715 Practice Test - Questions Answers, Page 14

Question list
Search
Search

List of questions

Search

Related questions











A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

A.

Port Bounce

A.

Port Bounce

Answers
B.

Reauth

B.

Reauth

Answers
C.

NoCoA

C.

NoCoA

Answers
D.

Disconnect

D.

Disconnect

Answers
Suggested answer: C

Explanation:

https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design

A network administrator must use Cisco ISE to check whether endpoints have the correct version of antivirus installed Which action must be taken to allow this capability?

A.

Configure a native supplicant profile to be used for checking the antivirus version

A.

Configure a native supplicant profile to be used for checking the antivirus version

Answers
B.

Configure Cisco ISE to push the HostScan package to the endpoints to check for the antivirus version.

B.

Configure Cisco ISE to push the HostScan package to the endpoints to check for the antivirus version.

Answers
C.

Create a Cisco AnyConnect Network Visibility Module configuration profile to send the antivirus information of the endpoints to Cisco ISE.

C.

Create a Cisco AnyConnect Network Visibility Module configuration profile to send the antivirus information of the endpoints to Cisco ISE.

Answers
D.

Create a Cisco AnyConnect configuration within Cisco ISE for the Compliance Module and associated configuration files

D.

Create a Cisco AnyConnect configuration within Cisco ISE for the Compliance Module and associated configuration files

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_client_prov.htmlAbout Anyconnect Network Visibility Module

https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect45/administration/guide/b_AnyConnect_Administrator_Guide_4-5/nvm.html

A network administrator must configura endpoints using an 802 1X authentication method with EAP identity certificates that are provided by the Cisco ISE When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network Which EAP type must be configured by the network administrator to complete this task?

A.

EAP-PEAP-MSCHAPv2

A.

EAP-PEAP-MSCHAPv2

Answers
B.

EAP-TTLS

B.

EAP-TTLS

Answers
C.

EAP-FAST

C.

EAP-FAST

Answers
D.

EAP-TLS

D.

EAP-TLS

Answers
Suggested answer: D

Explanation:

https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/certificaterequirements-eap-tls-peapabout EAP FAST

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html

Refer to the exhibit. An engineer is creating a new TACACS* command set and cannot use any show commands after togging into the device with this command set authorization Which configuration is causing this issue?

A.

Question marks are not allowed as wildcards for command sets.

A.

Question marks are not allowed as wildcards for command sets.

Answers
B.

The command set is allowing all commands that are not in the command list

B.

The command set is allowing all commands that are not in the command list

Answers
C.

The wildcard command listed is in the wrong format

C.

The wildcard command listed is in the wrong format

Answers
D.

The command set is working like an ACL and denying every command.

D.

The command set is working like an ACL and denying every command.

Answers
Suggested answer: A

An organization is migrating its current guest network to Cisco ISE and has 1000 guest users in the current database There are no resources to enter this information into the Cisco ISE database manually. What must be done to accomplish this task effciently?

A.

Use a CSV file to import the guest accounts

A.

Use a CSV file to import the guest accounts

Answers
B.

Use SOL to link me existing database to Ctsco ISE

B.

Use SOL to link me existing database to Ctsco ISE

Answers
C.

Use a JSON fie to automate the migration of guest accounts

C.

Use a JSON fie to automate the migration of guest accounts

Answers
D.

Use an XML file to change the existing format to match that of Cisco ISE

D.

Use an XML file to change the existing format to match that of Cisco ISE

Answers
Suggested answer: A

MacOS users are complaining about having to read through wordy instructions when remediating their workstations to gam access to the network Which alternate method should be used to tell users how to remediate?

A.

URL link

A.

URL link

Answers
B.

message text

B.

message text

Answers
C.

executable

C.

executable

Answers
D.

file distribution

D.

file distribution

Answers
Suggested answer: A

Explanation:

https://www.sciencedirect.com/topics/computer-science/remediation-action

Refer to the exhibit:

Refer to the exhibit Which component must be configured to apply the SGACL?

A.

egress router

A.

egress router

Answers
B.

host

B.

host

Answers
C.

secure server

C.

secure server

Answers
D.

ingress router

D.

ingress router

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/arch_over.html#52796

What does a fully distributed Cisco ISE deployment include?

A.

PAN and PSN on the same node while MnTs are on their own dedicated nodes.

A.

PAN and PSN on the same node while MnTs are on their own dedicated nodes.

Answers
B.

PAN and MnT on the same node while PSNs are on their own dedicated nodes.

B.

PAN and MnT on the same node while PSNs are on their own dedicated nodes.

Answers
C.

All Cisco ISE personas on their own dedicated nodes.

C.

All Cisco ISE personas on their own dedicated nodes.

Answers
D.

All Cisco ISE personas are sharing the same node.

D.

All Cisco ISE personas are sharing the same node.

Answers
Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_setup_cisco_ise.html

A network engineer has been tasked with enabling a switch to support standard web authentication for Cisco ISE. This must include the ability to provision for URL redirection on authentication Which two commands must be entered to meet this requirement? (Choose two)

A.

Ip http secure-authentication

A.

Ip http secure-authentication

Answers
B.

Ip http server

B.

Ip http server

Answers
C.

Ip http redirection

C.

Ip http redirection

Answers
D.

Ip http secure-server

D.

Ip http secure-server

Answers
E.

Ip http authentication

E.

Ip http authentication

Answers
Suggested answer: B, D

Explanation:

https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0111001.html

An engineer is configuring a dedicated SSID for onboarding devices. Which SSID type accomplishes this configuration?

A.

dual

A.

dual

Answers
B.

hidden

B.

hidden

Answers
C.

broadcast

C.

broadcast

Answers
D.

guest

D.

guest

Answers
Suggested answer: A

Explanation:

https://community.cisco.com/t5/security-documents/ise-byod-dual-vs-single-ssid-onboarding/tap/3641422

https://www.youtube.com/watch?v=HH_Xasqd9k4&ab_channel=CiscoISE-IdentityServicesEnginehttp://www.labminutes.com/sec0053_ise_1_1_byod_wireless_onboarding_dual_ssid

Total 242 questions
Go to page: of 25