Exams > Cisco > 300-715: Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)
300-715: Implementing and Configuring Cisco Identity Services Engine (300-715 SISE)
Page 7 out of 19 pages Questions 61-70 out of 184 questions
Question#61

Which two ports do network devices typically use for CoA? (Choose two.)

  • A. 19005
  • B. 443
  • C. 3799
  • D. 8080
  • E. 1700
Discover Answer Hide Answer

CE
Reference:
https://documentation.meraki.com/MR/Encryption_and_Authentication/Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points

Question#62

Which three default endpoint identity groups does Cisco ISE create? (Choose three.)

  • A. endpoint
  • B. unknown
  • C. block list
  • D. profiled
  • E. allow list
Discover Answer Hide Answer

BCD
Reference:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html#wp1203054

Question#63

An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the endpoints on the network.
Which node should be used to accomplish this task?

  • A. policy service
  • B. monitoring
  • C. primary policy administrator
  • D. pxGrid
Discover Answer Hide Answer

A

Question#64

An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types.
Which probe should be used to accomplish this task?

  • A. DHCP
  • B. DNS
  • C. NMAP
  • D. RADIUS
Discover Answer Hide Answer

A

Question#65

An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected.
Which service should be used to accomplish this task?

  • A. guest access
  • B. profiling
  • C. posture
  • D. client provisioning
Discover Answer Hide Answer

B

Question#66

An administrator for a small network is configuring Cisco ISE to provide dynamic network access to users. Management needs Cisco ISE to not automatically trigger a CoA whenever a profile change is detected. Instead, the administrator needs to verify the new profile and manually trigger a CoA.
What must be configured in the profiler to accomplish this goal?

  • A. Session Query
  • B. No CoA
  • C. Reauth
  • D. Port Bounce
Discover Answer Hide Answer

B
Reference:
https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-policies

Question#67

A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA.
Which action does the CoA perform?

  • A. It terminates the client session.
  • B. It applies the downloadable ACL provided in the CoA.
  • C. It triggers the NAD to reauthenticate the client.
  • D. It applies new permissions provided in the CoA to the client session.
Discover Answer Hide Answer

B
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html

Question#68

A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their workstation from the corporate network.
Which CoA configuration meets this requirement?

  • A. Reauth
  • B. Disconnect
  • C. No CoA
  • D. Port Bounce
Discover Answer Hide Answer

C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010100.html

Question#69

An organization is adding new profiling probes to the system to improve profiling on Cisco ISE. The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected.
What must be configured on the network device to accomplish this goal?

  • A. ICMP
  • B. WCCP
  • C. ARP
  • D. SNMP
Discover Answer Hide Answer

D
Reference:
https://en.wikipedia.org/wiki/Simple_Network_Management_Protocol

Question#70

An administrator is trying to collect metadata information about the traffic going across the network to gain added visibility into the hosts. This information will be used to create profiling policies for devices using Cisco ISE so that network access policies can be used.
What must be done to accomplish this task?

  • A. Configure the DHCP probe within Cisco ISE.
  • B. Configure NetFlow to be sent to the Cisco ISE appliance.
  • C. Configure the RADIUS profiling probe within Cisco ISE.
  • D. Configure SNMP to be used with the Cisco ISE appliance.
Discover Answer Hide Answer

B
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_asset_visibility.html

chevron rightPrevious Nextchevron right