Cisco 300-715 Practice Test - Questions Answers, Page 8
List of questions
Related questions
In a Cisco ISE split deployment model, which load is split between the nodes?
AAA
network admission
log collection
device admission
An engineer is implementing Cisco ISE and needs to configure 802.1X. The port settings are configured for port-based authentication. Which command should be used to complete this configuration?
dot1x pae authenticator
dot1x system-auth-control
authentication port-control auto
aaa authentication dot1x default group radius
Which two default endpoint identity groups does Cisco ISE create? (Choose two )
block list
endpoint
profiled
allow list
unknown
In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two )
publisher
administration
primary
policy service
subscriber
What happens when an internal user is configured with an external identity store for authentication, but an engineer uses the Cisco ISE admin portal to select an internal identity store as the identity source?
Authentication is redirected to the internal identity source.
Authentication is redirected to the external identity source.
Authentication is granted.
Authentication fails.
An engineer is configuring web authentication and needs to allow specific protocols to permit DNS traffic. Which type of access list should be used for this configuration?
reflexive ACL
extended ACL
standard ACL
numbered ACL
Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )
External TACACS Servers
Device Admin Service
Device Administration License
Server Sequence
Command Sets
A network engineer must enforce access control using special tags, without re-engineering the network design. Which feature should be configured to achieve this in a scalable manner?
SGT
dACL
VLAN
RBAC
An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node. Which persona should be configured with the largest amount of storage in this environment?
policy Services
Primary Administration
Monitoring and Troubleshooting
Platform Exchange Grid
An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected. Which service should be used to accomplish this task?
Profiling
Guest access
Client provisioning
Posture
Question