Cisco® 300-715 Exam Practice Questions (P. 3)
- Full Access (352 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
A network administrator must configure Cisco ISE Personas in the company to share session information via syslog.
Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?
Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?
- Aadmin
- Bpolicy services
- CmonitorMost Voted
- DpxGrid
Correct Answer:
C
C

The correct option for configuring Cisco ISE Personas to share session information via syslog is the monitor persona. This persona is designed specifically for logging and real-time analysis, collecting all event data. Although Cisco guidelines allow for policy services nodes (PSNs) to connect directly to syslog, they mainly facilitate policy decision operations and not session information sharing, which is the primary function of the monitoring persona. While other personas like admin and pxGrid play critical roles within the Cisco ISE architecture, they do not direct session data to syslog for logging and analysis purposes. Therefore, the monitor persona is the most appropriate choice for this task.
send
light_mode
delete
Question #22
What is the maximum number of PSN nodes supported in a medium-sized deployment?
- Atwo
- Bthree
- CfiveMost Voted
- Deight
Correct Answer:
C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/install_guide/b_ise_InstallationGuide26/b_ise_InstallationGuide_26_chapter_00.pdf
C
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/install_guide/b_ise_InstallationGuide26/b_ise_InstallationGuide_26_chapter_00.pdf
send
light_mode
delete
Question #23
How is policy services node redundancy achieved in a deployment?
- Aby creating a node group
- Bby deploying both primary and secondary node
- Cby enabling VIP
- Dby utilizing RADIUS server list on the NADMost Voted
Correct Answer:
B
B

The notion that deploying both primary and secondary nodes ensures policy service node redundancy is not necessarily correct, as the actual redundancy in a Cisco ISE environment is achieved through the configuration of a node group. When set up, this group allows any node within it to take over sessions from a failed node by sending a CoA to the NAD, effectively maintaining the continuity of policy enforcement regardless of individual node failures. Therefore, 'A' by creating a node group stands as a more accurate answer to ensure redundancy in deployment scenarios.
send
light_mode
delete
Question #24
Which two fields are available when creating an endpoint on the context visibility page of Cisco ISE? (Choose two.)
- ASecurity Group Tag
- BEndpoint Family
- CPolicy AssignmentMost Voted
- DIdentity Group AssignmentMost Voted
- EIP Address
Correct Answer:
CD
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010101.html
CD
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010101.html
send
light_mode
delete
Question #25
In which two ways can users and endpoints be classified for TrustSec? (Choose two.)
- AVLANMost Voted
- BdynamicMost Voted
- CQoS
- DSGACL
- ESXP
Correct Answer:
AD
AD

In TrustSec classification, the primary methods to classify users and endpoints are static and dynamic. Using VLANs relates to static classification, where a Security Group Tag (SGT) directly maps to an entity like a VLAN, allowing for simpler policy enforcement without the need for active authentication. On the other hand, SGACL, which is also a correct choice, involves dynamic security group tagging as part of broader access control measures, making TrustSec an adaptable solution catered to various network requirements. This dual functionality enables comprehensive and flexible identity management across Cisco networks.
send
light_mode
delete
Question #26
When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?
- AMIB
- BSIDMost Voted
- CMAB
- DTGT
Correct Answer:
B
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html
B
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html
send
light_mode
delete
Question #27
Which permission is common to the Active Directory Join and Leave operations?
- ARemove the Cisco ISE machine account from the domain.
- BSearch Active Directory to see if a Cisco ISE machine account already exists.Most Voted
- CSet attributes on the Cisco ISE machine account.
- DCreate a Cisco ISE machine account in the domain if the machine account does not already exist.
Correct Answer:
B
B

B, which concerns searching the Active Directory to check if a Cisco ISE machine account exists, is indeed the correct answer. This activity is requisite in both joining and leaving operations, being fundamentally utilized to verify the presence or absence of a machine account before any alterations are applied. Finding whether these accounts exist helps dictate the subsequent actions in either process, whether it's creation during joining or removal when leaving, ensuring the operations proceed accurately and effectively without redundancy or error.
send
light_mode
delete
Question #28
Which interface-level command is needed to turn on 802.1X authentication?
- Adot1x system-auth-control
- Bdot1x pae authenticatorMost Voted
- Caaa server radius dynamic-author
- Dauthentication host-mode single-host
Correct Answer:
B
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sg/configuration/guide/conf/dot1x.html
B
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sg/configuration/guide/conf/dot1x.html
send
light_mode
delete
Question #29
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?
- Asession-timeout
- Btermination-action
- Cradius-server timeout
- Didle-timeoutMost Voted
Correct Answer:
D
D
send
light_mode
delete
Question #30
What does the dot1x system-auth-control command do?
- Aglobally enables 802.1xMost Voted
- Bcauses a network access switch not to track 802.1x sessions
- Cenables 802.1x on a network access device interface
- Dcauses a network access switch to track 802.1x sessions
Correct Answer:
A
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/dot1x.html
A
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/dot1x.html
send
light_mode
delete
All Pages