Practice Free 300-715 Exam Online Questions
An engineer must use Cisco ISE profiler services to provide network access to Cisco IP phones that cannot support 802.1X. Cisco ISE is configured to use the access switch device sensor information system-description and platform-type to profile Cisco IP phones and allow access.
Which two protocols must be configured on the switch to complete the configuration? (Choose two.)
- A . EAPOL
- B . LLDP
- C . SNMP
- D . CDP
- E . STP
A network engineer is deploying Cisco ISE in a highly secure environment where the PSN will reside in a DMZ behind a firewall.
Which port must be permitted on the firewall so that users can access the sponsored guest portal from the internal network?
- A . UDP port 1812
- B . TCP port 8443
- C . UDP port 1645
- D . TCP port 8445
An administrator must deploy the Cisco Secure Client posture agent to employee endpoints that access a wireless network by using URL redirection in Cisco ISE. The compliance module must be downloaded from Cisco and uploaded to the Cisco ISE client provisioning resource.
What must be used to upload the compliance module?
- A . agent resources from the local disk
- B . Secure Client configuration
- C . Client Provisioning Portal
- D . Secure Client posture profile
A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices as part of the certificate enrollment process.
Which two features must be enabled to meet the requirement? (Choose two.)
- A . A certificate provisioning portal must be configured.
- B . Cisco ISE internal CA service must be enabled.
- C . A new BYOD portal must be created.
- D . Add SuperAdmin account into portal admin group.
- E . Define a certificate group tag.
A network consultant must create a captive portal for wireless guest users on a standalone Cisco ISE deployment. The customer wants guests to be redirected to https://guest.company.com and the real name of the standalone Cisco ISE node to remain hidden for security purposes.
Which two configurations must be performed to meet the requirement? (Choose two.)
- A . Change the guest portal FQDN on the portal settings in Cisco ISE.
- B . Add an SRV record for the FQDN of the DNS server.
- C . Add a static FQDN in the CWA Authorization Profile on Cisco ISE.
- D . Add a CNAME record for the FQDN of the Cisco ISE server.
- E . Add an AAAA record for the FQDN of the DNS server.
An administrator needs to add a new third party network device to be used with Cisco ISE for Guest and BYOD authorizations.
Which two features must be configured under Network Device Profile to achieve this? (Choose two.)
- A . SNMP community
- B . TACACS
- C . URL Redirect
- D . CoA Type
- E . dACL
What is used by the CA to issue a certificate to an endpoint?
- A . device unique identifier
- B . device network address
- C . certificate provisioning portal
- D . certificate template
An administrator must integrate Cisco ISE with Active Directory to provide a network operations team with GUI access to Cisco ISE.
These configurations were performed:
• joined Cisco ISE to Active Directory
• enabled administrative access for Active Directory
• set role-based access control permissions for the admin group
Which two actions must be performed to integrate Cisco ISE with Active Directory? (Choose two.)
- A . Configure a certificate authentication profile.
- B . Configure the EAP-GTC protocol.
- C . Select directory groups.
- D . Configure the admin group to AD group mapping.
- E . Select authorized users.
A network engineer must join a Cisco ISE appliance to an AD server in another subnet. A firewall separates the two subnets. The company’s security policy states that all protocols must use the secured version whenever possible.
Which two ports must be permitted on the firewall to allow Cisco ISE to authenticate users against the AD? (Choose two.)
- A . TCP 88
- B . UDP 123
- C . TCP 389
- D . TCP 636
- E . TCP 3268
