Practice Free 300-715 Exam Online Questions
An administrator must restrict access to the IP address of an application based on the browser version of the endpoint. Cisco ISE profiling services and guest portal access must be configured to capture the user-agent information of the endpoint from a Cisco switch using the Device Sensor feature.
These configurations were performed:
• added the switch to Cisco ISE
• configured device sensor on the switch
• enabled Cisco ISE portal access
• configured the user endpoint to connect to the Cisco ISE portal
Which type of probe must be enabled next to complete the configuration?
- A . RADIUS
- B . DHCP
- C . NetFlow
- D . SNMP
A network engineer is deploying Cisco ISE to provide network access control for a company. The company wants users on wired endpoints to be monitored and securely connected to the network without requiring the use of supplicants or certificates.
Which two components must be configured in Cisco ISE to meet this requirement? (Choose two.)
- A . MAB
- B . Cisco Secure Client
- C . RADIUS Server Proxy
- D . WebAuth
- E . Easy Connect
Which two responses from the RADIUS server to NAS are valid during the authentication process? (Choose two.)
- A . access-reserved
- B . access-challenge
- C . access-response
- D . access-request
- E . access-accept
Which two VMware features are supported on a Cisco ISE virtual appliance? (Choose two.)
- A . VM hardware version 7+
- B . OVF support
- C . VM cold migration
- D . multivendor integration
- E . VM snapshots
Which two profiling probes are enabled by default in Cisco ISE? (Choose two.)
- A . RADIUS
- B . NMAP
- C . DHCPSPAN
- D . NETFLOW
- E . HTTP
An engineer wants to use certificate authentication for endpoints that connect to a wired network integrated with Cisco ISE. The engineer needs to define the certificate field used as the principal username.
Which component would be needed to complete the configuration?
- A . authorization rule
- B . authentication policy
- C . authentication profile
- D . authorization profile
A network engineer is deploying Cisco ISE in an environment that contains multiple existing Cisco security products. The company needs policy and other user details to be shared between the existing security products and Cisco ISE.
Which Cisco ISE persona must be enabled to collect this data?
- A . Policy Service
- B . Administration
- C . Monitoring
- D . NpXGrid
Using the SAML protocol, an administrator must configure the Cisco ISE Sponsor portal to authenticate users with an external Microsoft Active Directory Federation Services server.
The configurations were performed:
• created a new SAML identity provider profile in Cisco ISE
• exported the service provider information
• configured all the required Active Directory Federation Services configurations
• imported the Active Directory Federation Services metadata
• configured groups in the new SAML identity
• added attributes to the new SAML identity provider profile
• configured Advanced Settings in the new SAML identity provider profile
Which two actions must be taken to complete the configuration? (Choose two.)
- A . Customize the Sponsor portal pages for integration with Active Directory Federation Services.
- B . Configure an identity source sequence in the Sponsor portal.
- C . Add SAML identity provider groups in Sponsor Group Members.
- D . Configure the Sponsor portal HTTPS port for Active Directory Federation Services integration.
- E . Allow Kerberos single sign-on on the Sponsor portal.
A network engineer is configuring a Cisco Wireless LAN Controller in order to find out more information about the devices that are connecting. This information must be sent to Cisco ISE to be used in authorization policies for profiling.
Which protocol must be configured in the Cisco Wireless LAN Controller to accomplish this task?
- A . ICMP
- B . DNS
- C . CDP
- D . DHCP
An administrator must block access to BYOD endpoints that were onboarded without a certificate and have been reported as stolen in the Cisco ISE My Devices Portal.
Which condition must be used when configuring an authorization policy that sets Deny Access permission?
- A . Endpoint Identity Group is Blocklist, and the BYOD state is Reinstate.
- B . Endpoint Identity Group is Blocklist, and the BYOD state is Lost.
- C . Endpoint Identity Group is Blocklist, and the BYOD state is Registered.
- D . Endpoint Identity Group is Blocklist, and the BYOD state is Pending.
