cisco 300-715 practice test

implementing and configuring cisco identity services engine (300-715 sise)

Last exam update: Sep 01 ,2024
Page 1 out of 28. Viewing questions 1-10 out of 275

Question 1

What is the purpose of the ip http server command on a switch?

  • A. It enables the https server for users for web authentication.
  • B. It enables dot1x authentication on the switch.
  • C. It enables MAB authentication on the switch.
  • D. It enables the switch to redirect users for web authentication.
Answer:

c

User Votes:
A
50%
B
50%
C
50%
D
50%

None

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the main deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out.
Which configuration is causing this behavior?

  • A. All of the nodes are actively being synched.
  • B. All of the nodes participate in the PAN auto failover.
  • C. One of the nodes is an active PSN.
  • D. One of the nodes is the Primary PAN.
Answer:

d

User Votes:
A
50%
B
50%
C
50%
D
50%

Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/Workflow/PDF/b_ISE_admin_24_pdf.pdf

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two.)

  • A. new AD user 802.1X authentication
  • B. hotspot
  • C. posture
  • D. guest AUP
  • E. BYOD
Answer:

bd

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

None

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 4

Which two probes provide IP-to-MAC address binding information to the ARP cache in Cisco ISE? (Choose two.)

  • A. HTTP
  • B. RADIUS
  • C. DHCP
  • D. DNS
  • E. NetFlow
Answer:

bc

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

None

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 5

To configure BYOD using Cisco ISE. an administrator is considering issuing certificates to the devices connecting to provide a better user experience. External CA servers cannot be used for this purpose because everything must be local to the Cisco ISE. What must be done to accomplish this?

  • A. Use the captive portal network assistant to issue certificates to the endpoints as they authenticate.
  • B. Use ISE as a sub CA for the BYOD portal and redirect users to the Root CA for certificate issuance.
  • C. Configure the Cisco ISE Internal CA to issue certificates to each endpoint connecting to the BYOD network.
  • D. Configure MS SCEP so that endpoints can query their local AD server for the correct certificate.
Answer:

c

User Votes:
A
50%
B
50%
C
50%
D
50%

None

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

What must be configured on the WLC to configure Central Web Authentication using Cisco ISE and a WLC?

  • A. Use the ip access-group webauth in command.
  • B. Use the radius-server vsa send authentication command.
  • C. Set the NAC State option to SNMP NAC.
  • D. Set the NAC State option to RADIUS NAC.
Answer:

d

User Votes:
A
50%
B
50%
C
50%
D
50%

Reference:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110001.pdf

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

  • A. VLAN to SGT mapping
  • B. IP Address to SGT mapping
  • C. L3IF to SGT mapping
  • D. Subnet to SGT mapping
Answer:

a

User Votes:
A
50%
B
50%
C
50%
D
50%

None

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

Which two default guest portals are available with Cisco ISE? (Choose two.)

  • A. WiFi-access
  • B. self-registered
  • C. central web authentication
  • D. visitor
  • E. sponsored
Answer:

be

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216330-ise-self-registered-guest-portal-configu.html

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 9

DRAG DROP

An engineer needs to configure a compliance policy on Cisco ISE to ensure that the latest encryption software is running on the C drive of all endpoints. Drag and drop the configuration steps from the left into the sequence on the right to accomplish this task.

Answer:

Discussions
0 / 1000

Question 10

An administrator is configuring a new profiling policy within Cisco ISE. The organization has several endpoints that are the same device type, and all have the same Block ID in their MAC address. The profiler does not currently have a profiling policy created to categorize these endpoints, therefore a custom profiling policy must be created.
Which condition must the administrator use in order to properly profile an ACME AI Connector endpoint for network access with MAC address 01:41:14:65:50:AB?

  • A. CDP_cdpCacheDeviceID_CONTAINS_
  • B. MAC_MACAddress_CONTAINS_
  • C. Radius_Called_Station-ID_STARTSWITH_
  • D. MAC_OUI_STARTSWITH_
Answer:

c

User Votes:
A
50%
B
50%
C
50%
D
50%

Reference:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-5/config-guide/b_wl_17_5_cg/m_radius-call-station-identifier.pdf

Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2