Jul-2024 Cisco 300-715 Certification Real 2024 Mock Exam [Q137-Q156]

Share

Jul-2024 Cisco 300-715 Certification Real 2024 Mock Exam

300-715 Exam Questions and Valid PMP Dumps PDF

NEW QUESTION # 137
Which two features must be used on Cisco ISE to enable the TACACS. feature? (Choose two)

  • A. Enable Device Admin Service
  • B. Device Administration License
  • C. Server Sequence
  • D. Command Sets
  • E. External TACACS Servers

Answer: A,B


NEW QUESTION # 138
A network engineer is configuring a network device that needs to filter traffic based on security group tags using a security policy on a routed into this task?

  • A. cts role-based policy priority-static
  • B. cts role-based enforcement
  • C. cts cache enable
  • D. cts authorization list

Answer: B


NEW QUESTION # 139
Which personas can a Cisco ISE node assume'?

  • A. policy service, gatekeeping, and monitoring
  • B. administration, policy service, gatekeeping
  • C. administration, monitoring, and gatekeeping
  • D. administration, policy service, and monitoring

Answer: D

Explanation:
Explanation
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html The persona or personas of a node determine the services provided by a node. An ISE node can assume any or all of the following personas: Administration, Policy Service, and Monitoring. The menu options that are available through the administrative user interface are dependent on the role and personas that an ISE node assumes. See Cisco ISE Nodes and Available Menu Options for more information.


NEW QUESTION # 140
An engineer is configuring Cisco ISE policies to support MAB for devices that do not have 802.1X capabilities. The engineer is configuring new endpoint identity groups as conditions to be used in the AuthZ policies, but noticed that the endpoints are not hitting the correct policies. What must be done in order to get the devices into the right policies?

  • A. Add an identity policy to dynamically add the IP address of the devices to their endpoint identity groups.
  • B. Create an AuthZ policy to identify Unknown devices and provide partial network access prior to profiling.
  • C. Identify the non 802.1X supported device types and create custom profiles for them to profile into.
  • D. Manually add the MAC addresses of the devices to endpoint ID groups in the context visibility database.

Answer: C


NEW QUESTION # 141
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.

Answer:

Explanation:

https://www.mbne.net/tech-notes/aaa-tacacs-radius


NEW QUESTION # 142
Which permission is common to the Active Directory Join and Leave operations?

  • A. Remove the Cisco ISE machine account from the domain.
  • B. Search Active Directory to see if a Cisco ISE machine account already ex.sts.
  • C. Create a Cisco ISE machine account in the domain if the machine account does not already exist
  • D. Set attributes on the Cisco ISE machine account

Answer: B

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html


NEW QUESTION # 143
Which two values are compared by the binary comparison function in authentication that is based on Active Directory?

  • A. user-presented password hash and a hash stored in Active Directory
  • B. MS-CHAPv2 provided machine credentials and credentials stored in Active Directory
  • C. subject alternative name and the common name
  • D. user-presented certificate and a certificate stored in Active Directory

Answer: C

Explanation:
Section: Policy Enforcement
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE- ADIntegration.html


NEW QUESTION # 144
Refer to the exhibit:

Refer to the exhibit Which switch configuration change will allow only one voice and one data endpoint on each port?

  • A. Multi-auth to multi-domain
  • B. Mab to dot1x
  • C. Auto to manual
  • D. Multi-auth to single-auth

Answer: A

Explanation:
https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907


NEW QUESTION # 145
Which term refers to an endpoint agent that tries to join an 802.1X-enabled network?

  • A. authenticator
  • B. EAP server
  • C. supplicant
  • D. client

Answer: C

Explanation:
Section: Endpoint Compliance


NEW QUESTION # 146
What are two requirements of generating a single signing in Cisco ISE by using a certificate provisioning portal, without generating a certificate request? (Choose two )

  • A. Location the CSV file for the device MAC
  • B. Enter the IP address of the device
  • C. Enter the common name
  • D. Select the certificate template
  • E. Choose the hashing method

Answer: C,D

Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provis


NEW QUESTION # 147
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.

Answer:

Explanation:


NEW QUESTION # 148
Which two default guest portals are available with Cisco ISE? (Choose two.)

  • A. central web authentication
  • B. visitor
  • C. self-registered
  • D. sponsored
  • E. WIFI-access

Answer: C,D


NEW QUESTION # 149
What is a characteristic of the UDP protocol?

  • A. UDP can detect when a server is down.
  • B. UDP can detect when a server is slow.
  • C. UDP offers information about a non-existent server.
  • D. UDP offers best-effort delivery.

Answer: D

Explanation:
Section: Network Access Device Administration
Explanation/Reference:


NEW QUESTION # 150
Select and Place

Answer:

Explanation:


NEW QUESTION # 151
Which protocol must be allowed for a BYOD device to access the BYOD portal?

  • A. HTTP
  • B. SMTP
  • C. SSH
  • D. HTTPS

Answer: D

Explanation:
Section: BYOD


NEW QUESTION # 152
Drag the descriptions on the left onto the components of 802.1X on the right.

Answer:

Explanation:


NEW QUESTION # 153
Which use case validates a change of authorization?

  • A. An endpoint that is disconnected from the network is discovered
  • B. An authenticated, wired EAP-capable endpoint is discovered
  • C. Endpoints are created through device registration for the guests
  • D. An endpoint profiling policy is changed for authorization policy.

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html


NEW QUESTION # 154
An administrator enables the profiling service for Cisco ISE to use for authorization policies while in closed mode. When the endpoints connect, they receive limited access so that the profiling probes can gather information and Cisco ISE can assign the correct profiles. They are using the default values within Cisco ISE. but the devices do not change their access due to the new profile. What is the problem'?

  • A. In closed mode, profiling does not work unless CDP is enabled.
  • B. The default profiler configuration is set to No CoA for the reauthentication setting
  • C. The profiling probes are not able to collect enough information to change the device profile
  • D. The profiler feed is not downloading new information so the profiler is inactive

Answer: B


NEW QUESTION # 155
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?

  • A. The secondary node restarts.
  • B. Both nodes restart.
  • C. The primary node restarts
  • D. The primary node becomes standalone

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/installation_guide/ise_install_guide/ise_deploy.html if your deployment has two nodes and you deregister the secondary node, both nodes in this primary-secondary pair are restarted. (The former primary and secondary nodes become standalone.)


NEW QUESTION # 156
......

300-715 Question Bank: Free PDF Download Recently Updated Questions: https://www.actualpdf.com/300-715_exam-dumps.html

300-715 Brain Dump: A Study Guide with Tips & Tricks for passing Exam: https://drive.google.com/open?id=1rUbCoCpJrTylgrAKUAYO3JIaOvt5v_d3