최신 300-715 무료덤프 - Cisco Implementing and Configuring Cisco Identity Services Engine
Which controller option allows a user to switch from the provisioning SSID to the employee SSID after registration?
정답: A
Which two ports do network devices typically use for CoA? (Choose two )
정답: A,C
설명: (DumpTOP 회원만 볼 수 있음)
Guest users report repeated prompts to authenticate with the portal when connecting to a wireless network. An administrator must configure Cisco ISE to reduce the number of prompts.
The solution must meet the requirements:
- Users must be authenticated once.
- When reconnecting to the visitor network, users do not need to be
redirected to the login page.
Which action completes the configuration?
The solution must meet the requirements:
- Users must be authenticated once.
- When reconnecting to the visitor network, users do not need to be
redirected to the login page.
Which action completes the configuration?
정답: D
An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as "Medical Switch" so that the policies can be made separately for the endpoints connecting through them. Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
A security administrator is using Cisco ISE to create a BYOD onboarding solution for all employees who use personal devices on the corporate network. The administrator generates a Certificate Signing Request and signs the request using an external Certificate Authority server.
Which certificate usage option must be selected when importing the certificate into ISE?
Which certificate usage option must be selected when importing the certificate into ISE?
정답: C
An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redirection and have their access restricted via an ACL. What must be configured in Cisco ISE to accomplish this task?
정답: C
A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps:
- An initial MAB request is sent to the Cisco ISE node.
- Cisco ISE responds with a URL redirection authorization profile if
the user's MAC address is unknown in the endpoint identity store.
- The URL redirection presents the user with an AUP acceptance page
when the user attempts to go to any URL.
Which authentication must the administrator configure on Cisco ISE?
- An initial MAB request is sent to the Cisco ISE node.
- Cisco ISE responds with a URL redirection authorization profile if
the user's MAC address is unknown in the endpoint identity store.
- The URL redirection presents the user with an AUP acceptance page
when the user attempts to go to any URL.
Which authentication must the administrator configure on Cisco ISE?
정답: C
Drag and Drop Question
An engineer needs to configure a compliance policy on Cisco ISE to ensure that the latest encryption software is running on the C drive of all endpoints. Drag and drop the configuration steps from the left into the sequence on the right to accomplish this task.
An engineer needs to configure a compliance policy on Cisco ISE to ensure that the latest encryption software is running on the C drive of all endpoints. Drag and drop the configuration steps from the left into the sequence on the right to accomplish this task.
정답:
A network administrator must configura endpoints using an 802 1X authentication method with EAP identity certificates that are provided by the Cisco ISE. When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network. Which EAP type must be configured by the network administrator to complete this task?
정답: A
설명: (DumpTOP 회원만 볼 수 있음)
An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.
What must be configured to accomplish this task?
What must be configured to accomplish this task?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Which statement is true?
정답: B
An engineer is deploying Cisco ISE to use 802.1X authentication for controlling access to the company's wired network. The request from company management is to minimize the impact on users during the rollout of 802.1X on the company switches. Which mode must be used first in a phased 802.1X deployment to fulfill this request?
정답: A
A network engineer has recently configured a remote branch router to authenticate to a centralized Cisco ISE server behind the corporate firewall using TACACS+. After making this configuration change, the engineer opened another SSH session to the router in order to verity that login attempts are now being sent to Cisco ISE, however that login attempt was unsuccessful. There are no connection attempts showing in the TACACS live log in Cisco ISE and the firewall administrator has verified that they see syslog and SNMP traffic destinated for the IP address of Cisco ISE, but no TACACS+ traffic. Which misconfiguration is the cause of the failed login?
정답: D
What is a difference between TACACS+ compared to RADIUS? (Choose two.)
정답: A,D
A network administrator notices that after a company-wide shut down, many users cannot connect their laptops to the corporate SSID.
What must be done to permit access in a timely manner?
What must be done to permit access in a timely manner?
정답: D
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is to ensure that the authentication procedure is disabled on the ports but still allows all endpoints to connect to the network. Which port-control option must the engineer configure?
정답: D
Which CLI command must be configured on the switchport to immediately run the MAB process if a non-802 1X capable endpoint connects to the port?
정답: C
An engineer is creating a new authorization policy to give the endpoints access to VLAN 310 upon successful authentication. The administrator tests the 802.1X authentication for the endpoint and sees that it is authenticating successfully. What must be done to ensure that the endpoint is placed into the correct VLAN?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
What allows an endpoint to obtain a digital certificate from Cisco ISE during a BYOD flow?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
The security team wants to secure the wired network. A legacy printer on the network with the MAC address 00:43:08:50:64:60 does not support 802.1X. Which setting must be enabled in the Allowed Authentication Protocols list in your Authentication Policy for Cisco ISE to support MAB for this MAC address?
정답: D