[2022] New 300-715 exam dumps Use Updated Cisco Exam
Verified 300-715 Dumps Q&As - 300-715 Test Engine with Correct Answers
NEW QUESTION 106
What are two components of the posture requirement when configuring Cisco ISE posture? (Choose two)
- A. conditions
- B. access policy
- C. updates
- D. Client Provisioning portal
- E. remediation actions
Answer: A,E
NEW QUESTION 107
An administrator is configuring TACACS+ on a Cisco switch but cannot authenticate users with Cisco ISE. The configuration contains the correct key of Cisc039712287. but the switch is not receiving a response from the Cisco ISE instance What must be done to validate the AAA configuration and identify the problem with the TACACS+ servers?
- A. Validate that the key value is correct using the test aaa authentication admin <key> legacy command.
- B. Test the user account on the server using the test aaa group radius server CUCS user admin pass <key> legacy command.
- C. Confirm the authorization policies are correct using the test aaa authorization admin drop legacy command.
- D. Check for server reachability using the test aaa group tacacs+ admin <key> legacy command.
Answer: D
Explanation:
Reference:
https://medium.com/training-course-ccna-security-210-260/ccna-security-part-3-implementing-aaa-in-cisco-ios-4b13ab285f51
NEW QUESTION 108
An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE.
What must be configured within Cisco ISE to accomplish this goal?
- A. Create a certificate signing request and have the root certificate authority sign it.
- B. Add an OCSP profile and configure the root certificate authority as secondary.
- C. Create an SCEP profile to link Cisco ISE with the root certificate authority.
- D. Add the root certificate authority to the trust store and enable it for authentication.
Answer: C
NEW QUESTION 109
How is policy services node redundancy achieved in a deployment?
- A. by utilizing RADIUS server list on the NAD
- B. by creating a node group
- C. by enabling VIP
- D. by deploying both primary and secondary node
Answer: D
NEW QUESTION 110
An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones The phones do not have the ability to authenticate via 802 1X Which command is needed on each switch port for authentication?
- A. enable network-authentication
- B. dot1x system-auth-control
- C. enable bypass-mac
- D. mab
Answer: D
Explanation:
Explanation
https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_aaa/configuration/15-2mt/sec-config-mab.html
NEW QUESTION 111
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?
- A. Both nodes restart.
- B. The secondary node restarts.
- C. The primary node restarts
- D. The primary node becomes standalone
Answer: A
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/installation_guide/ise_install_guide/ise_deploy.html if your deployment has two nodes and you deregister the secondary node, both nodes in this primary-secondary pair are restarted. (The former primary and secondary nodes become standalone.)
NEW QUESTION 112
Which two features must be used on Cisco ISE to enable the TACACS+ feature? (Choose two.)
- A. Device Admin Service
- B. Server Sequence
- C. Command Sets
- D. External TACACS Servers
- E. Device Administration License
Answer: A,E
Explanation:
Section: Network Access Device Administration
Explanation/Reference:
NEW QUESTION 113
An organization wants to standardize the 802 1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide What must be configured to accomplish this task?
- A. port security on the switch based on the client's information
- B. dynamic access list within the authorization profile
- C. extended access-list on the switch for the client
- D. security group tag within the authorization policy
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_sga_pol.html#
NEW QUESTION 114
Which statement about configuring certificates for BYOD is true?
- A. The SAN field is populated with the end user name.
- B. The CN field is populated with the endpoint host name.
- C. An endpoint certificate is mandatory for the Cisco ISE BYOD.
- D. An Android endpoint uses EST, whereas other operating systems use SCEP for enrollment.
Answer: C
Explanation:
Section: BYOD
NEW QUESTION 115
Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue. Which two requirements must be met to implement this change? (Choose two.)
- A. Provide domain administrator access to Active Directory.
- B. Configure a secure LDAP connection.
- C. Establish access to one Global Catalog server.
- D. Ensure that the NAT address is properly configured
- E. Enable IPC access over port 80.
Answer: A,C
NEW QUESTION 116
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles? (Choose two.)
- A. WLC
- B. ASA
- C. Shell
- D. IOS
- E. Firepower
Answer: A,C
Explanation:
Section: Network Access Device Administration
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2--1/admin_guide/b_ise_admin_guide_21/ b_ise_admin_guide_20_chapter_0100010.html
NEW QUESTION 117
An organization wants to improve their BYOD processes to have Cisco ISE issue certificates to the BYOD endpoints. Currently, they have an active certificate authority and do not want to replace it with Cisco ISE. What must be configured within Cisco ISE to accomplish this goal?
- A. Create a certificate signing request and have the root certificate authority sign it.
- B. Add an OCSP profile and configure the root certificate authority as secondary.
- C. Create an SCEP profile to link Cisco ISE with the root certificate authority.
- D. Add the root certificate authority to the trust store and enable it for authentication.
Answer: C
NEW QUESTION 118
An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?
- A. network scan probe
- B. NetFlow probe
- C. RADIUS probe
- D. HTTP probe
Answer: D
NEW QUESTION 119
A customer wants to set up the Sponsor portal and delegate the authentication flow to a third party for added security while using Kerberos Which database should be used to accomplish this goal?
- A. Active Directory
- B. LDAP
- C. RSA Token Server
- D. Local Database
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_01111.html#concept_srz_bkb_4db
NEW QUESTION 120
What is the condition that a Cisco ISE authorization policy cannot match?
- A. posture
- B. device type
- C. custom
- D. company contact
- E. time
Answer: C
NEW QUESTION 121
Refer to the exhibit:
Refer to the exhibit Which switch configuration change will allow only one voice and one data endpoint on each port?
- A. Multi-auth to multi-domain
- B. Multi-auth to single-auth
- C. Auto to manual
- D. Mab to dot1x
Answer: A
Explanation:
https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907
NEW QUESTION 122
Which supplicant(s) and server(s) are capable of supporting EAP-CHAINING?
- A. Cisco Secure Services Client and Cisco Access Control Server
- B. Cisco AnyConnect NAM and Cisco Access Control Server
- C. Cisco AnyConnect NAM and Cisco Identity Service Engine
- D. Windows Native Supplicant and Cisco Identity Service Engine
Answer: C
NEW QUESTION 123
An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?
- A. Client provisioning
- B. MDM
- C. My devices
- D. BYOD
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html
NEW QUESTION 124
An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate. What must be done in order to provide the CA this information?
- A. Generate the CSR.
- B. Download the intermediate server certificate.
- C. Download the CA server certificate.
- D. Install the Root CA and intermediate CA.
Answer: A
NEW QUESTION 125
Refer to the exhibit:
Refer to the exhibit. In which scenario does this switch configuration apply?
- A. when preventing users with hypervisor
- B. when allowing a hub with multiple clients connected
- C. when passing IP phone authentication
- D. when allowing multiple IP phones to be connected
Answer: B
Explanation:
https://www.linkedin.com/pulse/mac-authentication-bypass-priyanka-kumari#:~:text=Multi%2Dauthentication%20host%20mode%3A%20You,allows%20multiple%20source%20MAC%20addresses.
NEW QUESTION 126
......
Prerequisites
This certification exam has no official prerequisites. However, it is recommended that the candidates know about Cisco IOS Software Command-Line Interface, Cisco AnyConnect Secure Mobility Client, 802.1X, and Microsoft Windows OS. The intended audience for the test is ISE Administrators, Cisco Integrators and Partners, Wireless Network Security Engineers, and Network Security Engineers.
Pass Your 300-715 Dumps as PDF Updated on 2022 With 210 Questions: https://www.itexamsimulator.com/300-715-brain-dumps.html
Cisco 300-715 Real Exam Questions and Answers FREE: https://drive.google.com/open?id=1UZ40q81OA3VFHuBTGV7of2CZH1j131A1

