Cisco® 300-715 Exam Practice Questions (P. 5)
- Full Access (352 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
An administrator needs to connect ISE to Active Directory as an external authentication source and allow the proper ports through the firewall.
Which two ports should be opened to accomplish this task? (Choose two.)
Which two ports should be opened to accomplish this task? (Choose two.)
- ATELNET: 23
- BHTTPS: 443
- CHTTP: 80
- DLDAP: 389Most Voted
- EMSRPC:445Most Voted
Correct Answer:
DE
DE
send
light_mode
delete
Question #42
An engineer is implementing Cisco ISE and needs to configure 802.1X. The port settings are configured for port-based authentication.
Which command should be used to complete this configuration?
Which command should be used to complete this configuration?
- Aaaa authentication dot1x default group radius
- Bdot1x system-auth-controlMost Voted
- Cauthentication port-control auto
- Ddot1x pae authenticator
Correct Answer:
B
B
send
light_mode
delete
Question #43
DRAG DROP -
An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.
Select and Place:

An organization wants to implement 802.1X and is debating whether to use PEAP-MSCHAPv2 or PEAP-EAP-TLS for authentication. Drag the characteristics on the left to the corresponding protocol on the right.
Select and Place:

send
light_mode
delete
Question #44
DRAG DROP -
Drag the descriptions on the left onto the components of 802.1X on the right.
Select and Place:

Drag the descriptions on the left onto the components of 802.1X on the right.
Select and Place:

Correct Answer:
Authenticator ג€" device that controls physical access to the network based on the authentication status
Supplicant - software on the endpoint that communicates with EAP at layer 2
Authentication server ג€" device that validates the identity of the endpoint and provides results to another device
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/config-ieee-802x- pba.html

Authenticator ג€" device that controls physical access to the network based on the authentication status
Supplicant - software on the endpoint that communicates with EAP at layer 2
Authentication server ג€" device that validates the identity of the endpoint and provides results to another device
Reference:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/config-ieee-802x- pba.html
send
light_mode
delete
Question #45
A network engineer is configuring Cisco TrustSec and needs to ensure that the Security Group Tag is being transmitted between two devices.
Where in the Layer 2 frame should this be verified?
Where in the Layer 2 frame should this be verified?
- Apayload
- B802.1 AE header
- CCMD fieldMost Voted
- D802.1Q field
Correct Answer:
C
Reference:
https://www.cisco.com/c/dam/en/us/solutions/collateral/borderless-networks/trustsec/C07-730151-00_overview_of_trustSec_og.pdf
C
Reference:
https://www.cisco.com/c/dam/en/us/solutions/collateral/borderless-networks/trustsec/C07-730151-00_overview_of_trustSec_og.pdf
send
light_mode
delete
Question #46
A network administrator must configure endpoints using an 802.1X authentication method with EAP identity certificates that are provided by the Cisco ISE. When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network.
Which EAP type must be configured by the network administrator to complete this task?
Which EAP type must be configured by the network administrator to complete this task?
- AEAP-TTLS
- BEAP-TLSMost Voted
- CEAP-FAST
- DEAP-PEAP-MSCHAPv2
Correct Answer:
B
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html
B
Reference:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html
send
light_mode
delete
Question #47
An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.
What must be configured to accomplish this task?
What must be configured to accomplish this task?
- Adynamic access list within the authorization profileMost Voted
- Bextended access-list on the switch for the client
- Csecurity group tag within the authorization policy
- Dport security on the switch based on the client's information
Correct Answer:
C
C
send
light_mode
delete
Question #48

Refer to the exhibit.
In which scenario does this switch configuration apply?
- Awhen allowing a hub with multiple clients connectedMost Voted
- Bwhen allowing multiple IP phones to be connected
- Cwhen preventing users with hypervisor
- Dwhen bypassing IP phone authentication
Correct Answer:
A
Reference;
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/sec-user-8021x-xe-3se-5700-book/sec-ieee-802x-multi- auth.html
A
Reference;
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/sec-user-8021x-xe-3se-5700-book/sec-ieee-802x-multi- auth.html
send
light_mode
delete
Question #49

Refer to the exhibit.
Which switch configuration change will allow only one voice and one data endpoint on each port?
- Aauto to manual
- Bmab to dot1x
- Cmulti-auth to multi-domainMost Voted
- Dmulti-auth to single-auth
Correct Answer:
C
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/sec/b_166_sec_9300_cg/ configuring_ieee_802_1x_port_based_authentication.html
C
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/sec/b_166_sec_9300_cg/ configuring_ieee_802_1x_port_based_authentication.html
send
light_mode
delete
Question #50
A network security engineer needs to configure 802.1X port authentication to allow a single host to be authenticated for data and another single host to be authenticated for voice.
Which command should the engineer run on the interface to accomplish this goal?
Which command should the engineer run on the interface to accomplish this goal?
- Aauthentication host-mode multi-domainMost Voted
- Bauthentication host-mode single-host
- Cauthentication host-mode multi-auth
- Dauthentication host-mode multi-host
Correct Answer:
A
Reference:
https://www.pearsonitcertification.com/articles/article.aspx?p=1762597
A
Reference:
https://www.pearsonitcertification.com/articles/article.aspx?p=1762597
send
light_mode
delete
All Pages