Free 300-715 Exam Braindumps (page: 14)

Page 14 of 81

An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability.
Which probe must be used to accomplish this task?

  1. NetFlow probe
  2. HTTP probe
  3. RADIUS probe
  4. network scan probe

Answer(s): C


Reference:

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200292-Configure-Device-Sensor-for-ISE-Profilin.html



What is an advantage of using EAP-TLS over EAP-MS-CHAPv2 for client authentication?

  1. EAP-TLS uses a username and password for authentication to enhance security, while EAP-MS-CHAPv2 does not.
  2. EAP-TLS uses multiple forms of authentication, while EAP-MS-CHAPv2 only uses one.
  3. EAP-TLS uses a device certificate for authentication to enhance security, while EAP-MS-CHAPv2 does not.
  4. EAP-TLS secures the exchange of credentials, while EAP-MS-CHAPv2 does not.

Answer(s): C


Reference:

https://www.securew2.com/blog/eap-tls-vs-peap-mschapv2-which-authentication-protocol-is-superior



What must be configured on the WLC to configure Central Web Authentication using Cisco ISE and a WLC?

  1. Use the ip access-group webauth in command.
  2. Use the radius-server vsa send authentication command.
  3. Set the NAC State option to SNMP NA
  4. Set the NAC State option to RADIUS NAC.

Answer(s): D


Reference:

https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0110001.pdf



A network administrator is configuring authorization policies in Cisco ISE. There is a requirement to use AD group assignments to control access to network resources. After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work.
What is the cause of this issue?

  1. The AD join point is no longer connected.
  2. The certificate checks are not being conducted.
  3. The network devices ports are shut down.
  4. The AD DNS response time is slow.

Answer(s): A


Reference:

https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/b_ISE_AD_integration_2x.html#ID612



Page 14 of 81



Post your Comments and Discuss Cisco® 300-715 exam with other Community members:

Qorban commented on April 11, 2021
I paid in Derham and the process of payment and download was so fast and easy. The Test Engine called Xengine App came for free. I am stdying from that engine. For now I am not ready yet. But ones I go do my test I come back and write my score here so others can a more informed decision.
UNITED ARAB EMIRATES
upvote