Cisco 300-715 Practice Test - Questions Answers, Page 24
List of questions
Related questions
DRAG DROP
Drag and drop the configuration steps from the left into the sequence on the right to install two Cisco ISE nodes in a distributed deployment.
Which Cisco ISE deployment model is recommended for an enterprise that has over 50,000 concurrent active endpoints?
large deployment with fully distributed nodes running all personas
medium deployment with primary and secondary PAN/MnT/pxGrid nodes with shared PSNs
medium deployment with primary and secondary PAN/MnT/pxGrid nodes with dedicated PSNs
small deployment with one primary and one secondary node running all personas
What is a restriction of a standalone Cisco ISE node deployment?
Only the Policy Service persona can be disabled on the node.
The domain name of the node cannot be changed after installation.
Personas are enabled by default and cannot be edited on the node.
The hostname of the node cannot be changed after installation.
What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?
a primary and secondary PAN and a health check node for the Secondary PAN
a primary and secondary PAN and no health check nodes
a primary and secondary PAN and a pair of health check nodes
a primary and secondary PAN and a health check node for the Primary PAN
An administrator is attempting to join a new node to the primary Cisco ISE node, but receives the error message "Node is Unreachable". What is causing this error?
The second node is a PAN node.
No administrative certificate is available for the second node.
The second node is in standalone mode.
No admin privileges are available on the second node.
An administrator is configuring cisco ISE lo authenticate users logging into network devices using TACACS+ The administrator is not seeing any oí the authentication in the TACACS+ live logs. Which action ensures the users are able to log into the network devices?
Enable the device administration service in the Administration persona
Enable the session services in the administration persona
Enable the service sessions in the PSN persona.
Enable the device administration service in the PSN persona.
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?
authentication open
pae dot1x enabled
authentication host-mode multi-auth
monitor-mode enabled
The security team identified a rogue endpoint with MAC address 00:46:91:02:28:4A attached to the network. Which action must security engineer take within Cisco ISE to effectively restrict network access for this endpoint?
Configure access control list on network switches to block traffic.
Create authentication policy to force reauthentication.
Add MAC address to the endpoint quarantine list.
Implement authentication policy to deny access.
A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps:
. An initial MAB request is sent to the Cisco ISE node.
. Cisco ISE responds with a URL redirection authorization profile if the user's MAC address is unknown in the endpoint identity store.
. The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL.
Which authentication must the administrator configure on Cisco ISE?
device registration WebAuth
WLC with local WebAuth
wired NAD with local WebAuth
NAD with central WebAuth
An administrator is configuring cisco ISE lo authenticate users logging into network devices using TACACS+ The administrator is not seeing any o the authentication in the TACACS+ live logs. Which action ensures the users are able to log into the network devices?
Enable the device administration service in the Administration persona
Enable the session services in the administration persona
Enable the service sessions in the PSN persona.
Enable the device administration service in the PSN persona.
Question