Free 300-715 Exam Braindumps (page: 11)

Page 10 of 93

A network security administrator must integrate Cisco ISE with Active Directory. The administrator must carry out a join operation.
Which action must the security administrator take?

  1. Search Active Directory to see if admin user account exists
  2. Remove the ISE machine account from the domain
  3. Join Cisco ISE to the Active Directory domain
  4. Remove Cisco ISE user account from the domain.

Answer(s): C

Explanation:

To integrate Cisco Identity Services Engine (ISE) with Active Directory (AD), the ISE node must join the AD domain. This enables Cisco ISE to authenticate users and devices against the directory and enforce policies based on AD attributes.
Steps to Perform the Join Operation:
1. Navigate to Administration > Identity Management > External Identity Sources > Active Directory in the Cisco ISE GUI.
2. Provide the AD domain name and ensure network connectivity to the AD servers.
3. Use an AD account with appropriate privileges (often a domain admin or delegated account with join permissions) to perform the join operation.
4. After successful domain join, Cisco ISE can query the AD for user and group information.



A network security administrator must integrate Cisco ISE with Active Directory. The administrator must carry out a leave operation.
Which action on Active Directory is needed to meet the requirement?

  1. Remove the ISE machine account from the domain.
  2. Remove the ISE user account from the domain.
  3. Create ISE machine account to domain.
  4. Search Active Directory to see if admin user account exists.

Answer(s): A

Explanation:

Remove the ISE machine account from the domain.
This is the correct action because the machine account represents Cisco ISE in AD. Removing it effectively disconnects ISE from the domain.



Which two VMware features are supported on a Cisco ISE virtual appliance? (Choose two.)

  1. VM cold migration
  2. OVF support
  3. multivendor integration
  4. VM hardware version 7+
  5. VM snapshots

Answer(s): A,B

Explanation:

When deploying Cisco ISE as a virtual appliance on a VMware platform, there are specific VMware features that are supported and recommended:
VM Cold Migration:
Cisco ISE supports cold migration. This means that the virtual appliance can be moved from one host to another while it is powered off. Cold migration is a supported method for relocating the virtual machine in the event of hardware maintenance or upgrades.
OVF Support:
Cisco ISE is distributed as an OVF (Open Virtualization Format) package. This format is supported by VMware environments, making it straightforward to deploy the ISE virtual appliance using standard VMware tools.



A network security administrator wants to integrate Cisco ISE with Active Directory.
Which configuration action must the security administrator take to accomplish the task?

  1. Search Active Directory to see if admin user account exists.
  2. Remove the ISE machine account from the domain.
  3. Remove Cisco ISE user account from the domain.
  4. Join Cisco ISE to the Active Directory domain.

Answer(s): D

Explanation:

To integrate Cisco ISE with Active Directory, the security administrator must join Cisco ISE to the Active Directory domain. This allows ISE to authenticate users against Active Directory and apply identity-based policies.






Post your Comments and Discuss Cisco® 300-715 exam with other Community members:

Exam Discussions & Posts