ExamGecko
Home Home / Cisco / 300-715

Cisco 300-715 Practice Test - Questions Answers, Page 21

Question list
Search
Search

List of questions

Search

Related questions











A user is attempting to register a BYOD device to the Cisco ISE deployment, but needs to use the onboarding policy to request a digital certificate and provision the endpoint. What must be configured to accomplish this task?

A.

A native supplicant provisioning policy to redirect them to the BYOD portal for onboarding

A.

A native supplicant provisioning policy to redirect them to the BYOD portal for onboarding

Answers
B.

The Cisco AnyConnect provisioning policy to provision the endpoint for onboarding

B.

The Cisco AnyConnect provisioning policy to provision the endpoint for onboarding

Answers
C.

The BYOD flow to ensure that the endpoint will be provisioned prior to registering

C.

The BYOD flow to ensure that the endpoint will be provisioned prior to registering

Answers
D.

The posture provisioning policy to give the endpoint all necessary components prior to registering

D.

The posture provisioning policy to give the endpoint all necessary components prior to registering

Answers
Suggested answer: A

While configuring Cisco TrustSec on Cisco IOS devices the engineer must set the CTS device ID and password in order for the devices to authenticate with each other. However after this is complete the devices are not able to property authenticate What issue would cause this to happen even if the device ID and passwords are correct?

A.

The device aliases are not matching

A.

The device aliases are not matching

Answers
B.

The 5GT mappings have not been defined

B.

The 5GT mappings have not been defined

Answers
C.

The devices are missing the configuration cts credentials trustsec verify 1

C.

The devices are missing the configuration cts credentials trustsec verify 1

Answers
D.

EAP-FAST is not enabled

D.

EAP-FAST is not enabled

Answers
Suggested answer: B

An engineer is configuring a posture policy for Windows 10 endpoints and wants to ensure that users in each AD group have different conditions to meet to be compliant. What must be done to accomplish this task?

A.

identify The users groups needed for different policies and create service conditions to map each one to its posture requirement

A.

identify The users groups needed for different policies and create service conditions to map each one to its posture requirement

Answers
B.

Configure a simple condition for each AD group and use it in the posture policy for each use case

B.

Configure a simple condition for each AD group and use it in the posture policy for each use case

Answers
C.

Use the authorization policy within the policy set to group each AD group with their respective posture policy

C.

Use the authorization policy within the policy set to group each AD group with their respective posture policy

Answers
D.

Change the posture requirements to use an AD group lor each use case then use those requirements in the posture policy

D.

Change the posture requirements to use an AD group lor each use case then use those requirements in the posture policy

Answers
Suggested answer: C

An organization wants to enable web-based guest access for both employees and visitors The goal is to use a single portal for both user types Which two authentication methods should be used to meet this requirement? (Choose two )

A.

LDAP

A.

LDAP

Answers
B.

802 1X

B.

802 1X

Answers
C.

Certificate-based

C.

Certificate-based

Answers
D.

LOCAL

D.

LOCAL

Answers
E.

MAC based

E.

MAC based

Answers
Suggested answer: D, E

An organization is adding nodes to their Cisco ISE deployment and has two nodes designated as primary and secondary PAN and MnT nodes. The organization also has four PSNs An administrator is adding two more PSNs to this deployment but is having problems adding one of them What is the problem?

A.

The new nodes must be set to primary prior to being added to the deployment

A.

The new nodes must be set to primary prior to being added to the deployment

Answers
B.

The current PAN is only able to track a max of four nodes

B.

The current PAN is only able to track a max of four nodes

Answers
C.

Only five PSNs are allowed to be in the Cisco ISE cube if configured this way.

C.

Only five PSNs are allowed to be in the Cisco ISE cube if configured this way.

Answers
D.

One of the new nodes must be designated as a pxGrid node

D.

One of the new nodes must be designated as a pxGrid node

Answers
Suggested answer: C

Which two authentication protocols are supported by RADIUS but not by TACACS+? (Choose two.)

A.

MSCHAPv1

A.

MSCHAPv1

Answers
B.

PAP

B.

PAP

Answers
C.

EAP

C.

EAP

Answers
D.

CHAP

D.

CHAP

Answers
E.

MSCHAPV2

E.

MSCHAPV2

Answers
Suggested answer: C, E

What is a difference between RADIUS and TACACS+?

A.

RADIUS uses connection-oriented transport, and TACACS+ uses best-effort delivery.

A.

RADIUS uses connection-oriented transport, and TACACS+ uses best-effort delivery.

Answers
B.

RADIUS offers multiprotocol support, and TACACS+ supports only IP traffic.

B.

RADIUS offers multiprotocol support, and TACACS+ supports only IP traffic.

Answers
C.

RADIUS combines authentication and authorization functions, and TACACS+ separates them.

C.

RADIUS combines authentication and authorization functions, and TACACS+ separates them.

Answers
D.

RADIUS supports command accounting, and TACACS+ does not.

D.

RADIUS supports command accounting, and TACACS+ does not.

Answers
Suggested answer: C

An engineer is unable to use SSH to connect to a switch after adding the required CLI commands to the device to enable TACACS+. The device administration license has been added to Cisco ISE, and the required policies have been created. Which action is needed to enable access to the switch?

A.

The ip ssh source-interface command needs to be set on the switch

A.

The ip ssh source-interface command needs to be set on the switch

Answers
B.

802.1X authentication needs to be configured on the switch.

B.

802.1X authentication needs to be configured on the switch.

Answers
C.

The RSA keypair used for SSH must be regenerated after enabling TACACS+.

C.

The RSA keypair used for SSH must be regenerated after enabling TACACS+.

Answers
D.

The switch needs to be added as a network device in Cisco ISE and set to use TACACS+.

D.

The switch needs to be added as a network device in Cisco ISE and set to use TACACS+.

Answers
Suggested answer: D

The IT manager wants to provide different levels of access to network devices when users authenticate using TACACS+. The company needs specific commands to be allowed based on the Active Directory group membership of the different roles within the IT department. The solution must minimize the number of objects created in Cisco ISE. What must be created to accomplish this task?

A.

one shell profile and one command set

A.

one shell profile and one command set

Answers
B.

multiple shell profiles and one command set

B.

multiple shell profiles and one command set

Answers
C.

one shell profile and multiple command sets

C.

one shell profile and multiple command sets

Answers
D.

multiple shell profiles and multiple command sets

D.

multiple shell profiles and multiple command sets

Answers
Suggested answer: C

What are two differences of TACACS+ compared to RADIUS? (Choose two.)

A.

TACACS+ uses a connectionless transport protocol, whereas RADIUS uses a connection-oriented transport protocol.

A.

TACACS+ uses a connectionless transport protocol, whereas RADIUS uses a connection-oriented transport protocol.

Answers
B.

TACACS+ encrypts the full packet payload, whereas RADIUS only encrypts the password.

B.

TACACS+ encrypts the full packet payload, whereas RADIUS only encrypts the password.

Answers
C.

TACACS+ only encrypts the password, whereas RADIUS encrypts the full packet payload.

C.

TACACS+ only encrypts the password, whereas RADIUS encrypts the full packet payload.

Answers
D.

TACACS+ uses a connection-oriented transport protocol, whereas RADIUS uses a connectionless transport protocol.

D.

TACACS+ uses a connection-oriented transport protocol, whereas RADIUS uses a connectionless transport protocol.

Answers
E.

TACACS+ supports multiple sessions per user, whereas RADIUS supports one session per user.

E.

TACACS+ supports multiple sessions per user, whereas RADIUS supports one session per user.

Answers
Suggested answer: B, D
Total 242 questions
Go to page: of 25