Pass 300-715 Brain Dump Updated Certification Sample Questions
Online 300-715 Test Brain Dump Question and Test Engine
NEW QUESTION # 88
A user changes the status of a device to stolen in the My Devices Portal of Cisco ISE. The device was originally onboarded in the BYOD wireless Portal without a certificate. The device is found later, but the user cannot re-onboard the device because Cisco ISE assigned the device to the Blocklist endpoint identity group. What must the user do in the My Devices Portal to resolve this issue?
- A. Change the BYOD registration attribute of the device to None.
- B. Change the device state from Stolen to Not Registered.
- C. Manually remove the device from the Blocklist endpoint identity group.
- D. Delete the device, and then re-add the device.
Answer: B
NEW QUESTION # 89
Which two methods should a sponsor select to create bulk guest accounts from the sponsor portal? (Choose two )
- A. Known
- B. Daily
- C. Random
- D. Imported
- E. Monthly
Answer: C,D
NEW QUESTION # 90
What is a function of client provisioning?
- A. It checks a dictionary' attribute with a value.
- B. It ensures that endpoints receive the appropriate posture agents
- C. It ensures an application process is running on the endpoint.
- D. It checks the existence date and versions of the file on a client.
Answer: B
NEW QUESTION # 91
The IT manager wants to provide different levels of access to network devices when users authenticate using TACACS+. The company needs specific commands to be allowed based on the Active Directory group membership of the different roles within the IT department. The solution must minimize the number of objects created in Cisco ISE. What must be created to accomplish this task?
- A. one shell profile and multiple command sets
- B. multiple shell profiles and one command set
- C. one shell profile and one command set
- D. multiple shell profiles and multiple command sets
Answer: D
Explanation:
We need Different Commands based on Different AD Groups, we will need Multiple shell profiles and Multiple command sets.
NEW QUESTION # 92
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE. The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- B. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
- C. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- D. Confirm the authorization policies are correct using the test aaa authorization admin drop legacy command.
Answer: B
Explanation:
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4b13ab285f51
NEW QUESTION # 93
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is to ensure that the authentication procedure is disabled on the ports but still allows all endpoints to connect to the network. Which port-control option must the engineer configure?
- A. force-unauthorized
- B. force-authorized
- C. auto
- D. pae-disabled
Answer: B
NEW QUESTION # 94
Due to a recent network incident, all access to network devices must be centrally logged and tracked in Cisco ISE. On which nodes must the Device Admin service be enabled?
- A. each PSN
- B. each PAN
- C. one PSN
- D. one PAN
Answer: A
NEW QUESTION # 95
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out Which configuration is causing this behavior?
- A. All of the nodes are actively being synched.
- B. All of the nodes participate in the PAN auto failover.
- C. One of the nodes is the Primary PAN
- D. One of the nodes is an active PSN.
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_deployment.html#ID185
NEW QUESTION # 96
When setting up profiling in an environment using Cisco ISE for network access control, an organization must use non-proprietary protocols for collecting the information at layer 2. Which two probes will provide this information without forwarding SPAN packets to Cisco ISE? {Choose two.)
- A. RADIUS probe
- B. DNS probe
- C. DHCP SPAN probe
- D. NetFlow probe
- E. SNMP query probe
Answer: B,C
NEW QUESTION # 97
A user reports that the RADIUS accounting packets are not being seen on the Cisco ISE server.
Which command is the user missing in the switch's configuration?
- A. radius-server vsa send accounting
- B. aaa accounting resource default start-stop group radius
- C. aaa accounting exec default start-stop group radios
- D. aaa accounting network default start-stop group radius
Answer: D
Explanation:
Beginning from Cisco IOS version 15.2(1)E / XE 3.5.0E , the VSA commands are enabled by default. To disbale VSA, the "no" option must be used.
NEW QUESTION # 98
A network engineer is configuring a network device that needs to filter traffic based on security group tags using a security policy on a routed into this task?
- A. cts authorization list
- B. cts role-based enforcement
- C. cts cache enable
- D. cts role-based policy priority-static
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/xe-16/sec-usr-cts-xe-
16-book/sec-cts-sgacl.html
NEW QUESTION # 99
An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node.
Which persona should be configured with the largest amount of storage in this environment?
- A. policy Services
- B. Platform Exchange Grid
- C. Monitoring and Troubleshooting
- D. Primary Administration
Answer: D
NEW QUESTION # 100
During BYOD flow, from where does a Microsoft Windows PC download the Network Setup Assistant?
- A. Cisco App Store
- B. Microsoft App Store
- C. Cisco ISE directly
- D. Native OTA functionality
Answer: C
Explanation:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/BYOD-configuration
NEW QUESTION # 101
A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA Which action does the CoA perform?
- A. It triggers the NAD to reauthenticate the client
- B. It terminates the client session
- C. It applies the downloadable ACL provided in the CoA
- D. It applies new permissions provided in the CoA to the client session.
Answer: C
Explanation:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/113362-config-web-auth-ise-00.html
NEW QUESTION # 102
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)
- A. IOS
- B. Firepower
- C. ASA
- D. Shell
- E. WLC
Answer: D,E
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide TACACS+ Profile TACACS+ profiles control the initial login session of the device administrator. A session refers to each individual authentication, authorization, or accounting request. A session authorization request to a network device elicits an ISE response. The response includes a token that is interpreted by the network device, which limits the commands that may be executed for the duration of a session. The authorization policy for a device administration access service can contain a single shell profile and multiple command sets. The TACACS+ profile definitions are split into two components:
* Common tasks
* Custom attributes
There are two views in the TACACS+ Profiles page (Work Centers > Device Administration > Policy Elements > Results > TACACS Profiles)-Task Attribute View and Raw View. Common tasks can be entered using the Task Attribute View and custom attributes can be created in the Task Attribute View as well as the Raw View.
The Common Tasks section allows you to select and configure the frequently used attributes for a profile. The attributes that are included here are those defined by the TACACS+ protocol draft specifications. However, the values can be used in the authorization of requests from other services. In the Task Attribute View, the ISE administrator can set the privileges that will be assigned to the device administrator. The common task types are:
* Shell
* WLC
* Nexus
* Generic
The Custom Attributes section allows you to configure additional attributes. It provides a list of attributes that are not recognized by the Common Tasks section. Each definition consists of the attribute name, an indication of whether the attribute is mandatory or optional, and the value for the attribute. In the Raw View, you can enter the mandatory attributes using a equal to (=) sign between the attribute name and its value and optional attributes are entered using an asterisk (*) between the attribute name and its value. The attributes entered in the Raw View are reflected in the Custom Attributes section in the Task Attribute View and vice versa. The Raw View is also used to copy paste the attribute list (for example, another product's attribute list) from the clipboard onto ISE. Custom attributes can be defined for nonshell services.
NEW QUESTION # 103
A laptop was stolen and a network engineer added it to the block list endpoint identity group What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access?
- A. Ensure that access to port 8443 is allowed within the ACL.
- B. Select DenyAccess within the authorization policy.
- C. Ensure that access to port 8444 is allowed within the ACL.
- D. Select DROP under If Auth fail within the authentication policy.
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010000.html
NEW QUESTION # 104
What are the three default behaviors of Cisco ISE with respect to authentication, when a user connects to a switch that is configured for 802.1X, MAB, and WebAuth? (Choose three)
- A. Unmatched traffic is allowed on the network.
- B. Dot1X traffic uses a user-defined identity store for retrieving identity.
- C. Unmatched traffic is dropped because of the Reject/Reject/Drop action that is configured under Options.
- D. MAB traffic uses internal endpoints for retrieving identity.
- E. Dot1 traffic uses internal users for retrieving identity.
Answer: C,D,E
NEW QUESTION # 105
Select and Place
Answer:
Explanation:
NEW QUESTION # 106
An engineer must use Cisco ISE profiler services to provide network access to Cisco IP phones that cannot support 802.1X. Cisco ISE is configured to use the access switch device sensor information system-description and platform-type to profile Cisco IP phones and allow access.
Which two protocols must be configured on the switch to complete the configuration? (Choose two.)
- A. LLDP
- B. SNMP
- C. STP
- D. EAPOL
- E. CDP
Answer: A,E
NEW QUESTION # 107
An organization is adding new profiling probes to the system to improve profiling on Oseo ISE The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected What must be configured on the network device to accomplish this goal?
- A. WCCP
- B. ARP
- C. SNMP
- D. ICMP
Answer: C
Explanation:
https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-790343135
NEW QUESTION # 108
A Cisco device has a port configured in multi-authentication mode and is accepting connections only from hosts assigned the SGT of SGT_0422048549 The VLAN trunk link supports a maximum of 8 VLANS What is the reason for these restrictions?
- A. The device is performing mime tagging while acting as a SXP speaker
- B. The device is performing inline tagging without acting as a SXP speaker
- C. The IP subnet addresses are statically mapped to an SGT
- D. The IP subnet addresses are dynamically mapped to an SGT.
Answer: D
NEW QUESTION # 109
An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the endpoints on the network. Which node should be used to accomplish this task?
- A. PSN
- B. MnT
- C. primary PAN
- D. pxGrid
Answer: A
NEW QUESTION # 110
......
Real Cisco 300-715 Exam Dumps with Correct 347 Questions and Answers: https://www.vceprep.com/300-715-latest-vce-prep.html
Cisco 300-715 Certification Real 2024 Mock Exam: https://drive.google.com/open?id=1WsoJTU5BKTD1wq3FEZqXBy6YvpIXluT3