Cisco® 300-715 Exam Practice Questions (P. 4)
- Full Access (369 questions)
 - Six months of Premium Access
 - Access to one million comments
 - Seamless ChatGPT Integration
 
- Ability to download PDF files
 - Anki Flashcard files for revision
 - No Captcha & No AdSense
 - Advanced Exam Configuration
 
Question #31
                                    What should be configured on the Cisco ISE authentication policy for unknown MAC addresses/identities for successful authentication?
                                
                              
          
          send
        
        
          light_mode
          delete
      
    Question #32
                                    Which command displays all 802.1X/MAB sessions that are active on the switch ports of a Cisco Catalyst switch?
                                
                              - Ashow authentication sessions interface Gi1/0/x output
 - Bshow authentication sessionsMost Voted
 - Cshow authentication sessions output
 - Dshow authentication sessions interface Gi 1/0/x
 
                                        Correct Answer:
D
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-xe-3se-3850-cr-book/sec-s1-xe-3se-3850-cr- book_chapter_01.html#wp3404908137
                                   
                                    D
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-xe-3se-3850-cr-book/sec-s1-xe-3se-3850-cr- book_chapter_01.html#wp3404908137
          
          send
        
        
          light_mode
          delete
      
    Question #33
                                    What are two requirements of generating a single certificate in Cisco ISE by using a certificate provisioning portal, without generating a certificate signing request?
(Choose two.)
                                
                              (Choose two.)
- AEnter the IP address of the device.
 - BEnter the common name.Most Voted
 - CChoose the hashing method.
 - DLocate the CSV file for the device MAC.
 - ESelect the certificate template.Most Voted
 
                                        Correct Answer:
BE
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html
                                   
                                    BE
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html
          
          send
        
        
          light_mode
          delete
      
    Question #34

Refer to the exhibit. Which command is typed within the CLI of a switch to view the troubleshooting output?
- Ashow authentication sessions mac 000e.84af.59af detailsMost Voted
 - Bshow authentication registrations
 - Cshow authentication interface gigabitethernet2/0/36
 - Dshow authentication sessions method
 
                                        Correct Answer:
A
                                        
                                        
                                            
                                        
                                    
                                   
                                    A
          
          send
        
        
          light_mode
          delete
      
    Question #35
                                    What gives Cisco ISE an option to scan endpoints for vulnerabilities?
                                
                              - Aauthentication policy
 - Bauthorization profileMost Voted
 - Cauthentication profile
 - Dauthorization policy
 
                                        Correct Answer:
B
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010100.html
                                   
                                    B
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010100.html
          
          send
        
        
          light_mode
          delete
      
    Question #36
                                    Which two values are compared by the binary comparison function in authentication that is based on Active Directory?
                                
                              - Auser-presented certificate and a certificate stored in Active DirectoryMost Voted
 - BMS-CHAPv2 provided machine credentials and credentials stored in Active Directory
 - Cuser-presented password hash and a hash stored in Active Directory
 - Dsubject alternative name and the common name
 
                                        Correct Answer:
D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html
                                   
                                    D
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.html
          
          send
        
        
          light_mode
          delete
      
    Question #37
                                    What happens when an internal user is configured with an external identity store for authentication, but an engineer uses the Cisco ISE admin portal to select an internal identity store as the identity source?
                                
                              - AAuthentication is redirected to the internal identity source.
 - BAuthentication is granted.
 - CAuthentication fails.Most Voted
 - DAuthentication is redirected to the external identity source.
 
                                        Correct Answer:
D
                                        
                                        
                                            
                                        
                                    
                                   
                                    D
          
          send
        
        
          light_mode
          delete
      
    Question #38
                                    Which two actions occur when a Cisco ISE server device administrator logs in to a device? (Choose two.)
                                
                              - AThe Cisco ISE server queries the internal identity store.Most Voted
 - BThe device queries the external identity store.
 - CThe device queries the Cisco ISE authorization server.
 - DThe device queries the internal identity store.
 - EThe Cisco ISE server queries the external identity store.Most Voted
 
                                        Correct Answer:
BE
                                        
                                        
                                            
                                        
                                    
                                   
                                    BE
          
          send
        
        
          light_mode
          delete
      
    Question #39
                                    An engineer is configuring a guest password policy and needs to ensure that the password complexity requirements are set to mitigate brute force attacks.
Which two requirements should be included in this policy? (Choose two.)
                                
                              Which two requirements should be included in this policy? (Choose two.)
- Aactive username limit
 - Bpassword expiration periodMost Voted
 - Caccess code control
 - Dusername expiration date
 - Eminimum password lengthMost Voted
 
                                        Correct Answer:
BE
                                        
                                        
                                            
                                        
                                    
                                   
                                    BE
          
          send
        
        
          light_mode
          delete
      
    Question #40
                                    An engineer is using the low-impact mode for a phased deployment of Cisco ISE and is trying to connect to the network prior to authentication.
Which access will be denied in this deployment?
                                
                              Which access will be denied in this deployment?
          
          send
        
        
          light_mode
          delete
      
    All Pages
