Cisco 300-715 Practice Test - Questions Answers, Page 15
List of questions
Related questions
An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?
HTTP probe
NetFlow probe
network scan probe
RADIUS probe
An administrator is trying to collect metadata information about the traffic going across the network to gam added visibility into the hosts. This Information will be used to create profiling policies for devices us mg Cisco ISE so that network access policies can be used What must be done to accomplish this task?
Configure the RADIUS profiling probe within Cisco ISE
Configure NetFlow to be sent to me Cisco ISE appliance.
Configure SNMP to be used with the Cisco ISE appliance
Configure the DHCP probe within Cisco ISE
A laptop was stolen and a network engineer added it to the block list endpoint identity group What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access?
Select DenyAccess within the authorization policy.
Ensure that access to port 8443 is allowed within the ACL.
Ensure that access to port 8444 is allowed within the ACL.
Select DROP under If Auth fail within the authentication policy.
An adminístrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs. Besides defining a new shell profile in Cisco ISE. what must be done to accomplish this configuration?
Enable the privilege levels in Cisco ISE
Enable the privilege levels in the IOS devices.
Define the command privileges for levels 2-5 in the IOS devices
Define the command privileges for levels 2-5 in Cisco ISE
An administrator is configuring RADIUS on a Cisco switch with a key set to Cisc403012128 but is receiving the error "Authentication failed: 22040 Wrong password or invalid shared secret. "what must be done to address this issue?
Add the network device as a NAD inside Cisco ISE using the existing key.
Configure the key on the Cisco ISE instead of the Cisco switch.
Use a key that is between eight and ten characters.
Validate that the key is correct on both the Cisco switch as well as Cisco ISE.
What is the maximum number of PSN nodes supported in a medium-sized deployment?
three
five
two
eight
An organization has a fully distributed Cisco ISE deployment When implementing probes, an administrator must scan for unknown endpoints to learn the IP-to-MAC address bindings. The scan is complete on one FPSN. but the information is not available on the others. What must be done to make the information available?
Scanning must be initiated from the PSN that last authenticated the endpoint
Cisco ISE must learn the IP-MAC binding of unknown endpoints via DHCP profiling, not via scanning
Scanning must be initiated from the MnT node to centrally gather the information
Cisco ISE must be configured to learn the IP-MAC binding of unknown endpoints via RADIUS authentication, not via scanning
An administrator is configuring a new profiling policy within Cisco ISE The organization has several endpoints that are the same device type and all have the same Block ID in their MAC address. The profiler does not currently have a profiling policy created to categorize these endpoints. therefore a custom profiling policy must be created Which condition must the administrator use in order to properly profile an ACME Al Connector endpoint for network access with MAC address <MAC ADDRESS>?
MAC_OUI_STARTSWITH_<MACADDRESS>
CDP_cdpCacheDevicelD_CONTAINS_<MACADDRESS>
MAC_MACAddress_CONTAINS_<MACADDRESS>
Radius Called Station-ID STARTSWITH <MACADDRESS>
A network administrator is configuring client provisioning resource policies for client machines and must ensure that an agent pop-up is presented to the client when attempting to connect to the network Which configuration item needs to be added to allow for this'?
the client provisioning URL in the authorization policy
a temporal agent that gets installed onto the system
a remote posture agent proxying the network connection
an API connection back to the client
A network administrator must configure Cisco SE Personas in the company to share session information via syslog. Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?
pxGrid
admin
policy services
monitor
Question