최신 300-715 무료덤프 - Cisco Implementing and Configuring Cisco Identity Services Engine
An organization is implementing Cisco ISE posture services and must ensure that a host-based firewall is in place on every Windows and Mac computer that attempts to access the network.
They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this.
What should be done to enable this type of posture check?
They have multiple vendors' firewall applications for their devices, so the engineers creating the policies are unable to use a specific application check in order to validate the posture for this.
What should be done to enable this type of posture check?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Which port does Cisco ISE use for native supplicant provisioning of a Windows laptop?
정답: B
설명: (DumpTOP 회원만 볼 수 있음)
An engineer must use Cisco ISE profiler services to provide network access to Cisco IP phones that cannot support 802.1X. Cisco ISE is configured to use the access switch device sensor information system-description and platform-type to profile Cisco IP phones and allow access.
Which two protocols must be configured on the switch to complete the configuration? (Choose two.)
Which two protocols must be configured on the switch to complete the configuration? (Choose two.)
정답: B,C
Which types of design are required in the Cisco ISE ATP program?
정답: D
An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites.
Which configuration must be applied on Cisco ISE?
Which configuration must be applied on Cisco ISE?
정답: A
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for one day. When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
정답: D
What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?
정답: C
An engineer has been tasked with standing up a new guest portal for customers that are waiting in the lobby. There is a requirement to allow guests to use their social media logins to access the guest network to appeal to more customers. What must be done to accomplish this task?
정답: A
A technician must configure MAB on an access switch. Due to a protocol error, the engineer discovers that MAB cannot authenticate. For MAB to function, which protocol must be enabled in the authorized protocol lists?
정답: D
An employee must access the internet through the corporate network from a new mobile device that does not support native supplicant provisioning provided by Cisco ISE.
Which portal must the employee use to provision to the device?
Which portal must the employee use to provision to the device?
정답: A
A network engineer is configuring Cisco TrustSec and needs to ensure that the Security Group Tag is being transmitted between two devices.
Where in the Layer 2 frame should this be verified?
Where in the Layer 2 frame should this be verified?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Which two actions must be verified to confirm that the internet is accessible via guest access when configuring a guest portal? (Choose two.)
정답: C,E
A user is attempting to register a BYOD device to the Cisco ISE deployment, but needs to use the onboarding policy to request a digital certificate and provision the endpoint.
What must be configured to accomplish this task?
What must be configured to accomplish this task?
정답: B
An administrator must provide administrative access to the helpdesk users on production Cisco IOS routers. The solution must meet these requirements:
- Authenticate the users against Microsoft AD.
- Validate IOS commands run by users.
These configurations have been performed:
- joined Cisco ISE to AD
- retrieved AD groups
- added a router to Cisco ISE
- enabled Device Admin Service in Cisco ISE
- configured an authorization policy
- configured the routers for authentication and authorization
Which two components must be configured? (Choose two.)
- Authenticate the users against Microsoft AD.
- Validate IOS commands run by users.
These configurations have been performed:
- joined Cisco ISE to AD
- retrieved AD groups
- added a router to Cisco ISE
- enabled Device Admin Service in Cisco ISE
- configured an authorization policy
- configured the routers for authentication and authorization
Which two components must be configured? (Choose two.)
정답: D,E
What are two benefits of TACACS+ versus RADIUS for device administration? (Choose two )
정답: A,B
A network engineer must configure a centralized Cisco ISE solution for wireless guest access with users in different time zones. The guest account activation time must be independent of the user time zone, and the guest account must be enabled automatically when the user self- registers on the guest portal. Which option in the time profile settings must be selected to meet the requirement?
정답: B
Guest users report repeated prompts to authenticate with the portal when connecting to a wireless network. An administrator must configure Cisco ISE to reduce the number of prompts.
The solution must meet the requirements:
- Users must be authenticated once.
- When reconnecting to the visitor network, users do not need to be
redirected to the login page.
Which action completes the configuration?
The solution must meet the requirements:
- Users must be authenticated once.
- When reconnecting to the visitor network, users do not need to be
redirected to the login page.
Which action completes the configuration?
정답: D
During BYOD flow, from where does a Microsoft Windows PC download the Network Setup Assistant?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
The profiling data from network access devices is sent to which Cisco ISE node?
정답: C