Free 300-715 Exam Braindumps (page: 18)

Page 17 of 93

A network administrator must configure endpoints using an 802.1X authentication method with EAP identity certificates that are provided by the Cisco ISE.
When the endpoint presents the identity certificate to Cisco ISE to validate the certificate, endpoints must be authorized to connect to the network.
Which EAP type must be configured by the network administrator to complete this task?

  1. EAP-TTLS
  2. EAP-TLS
  3. EAP-FAST
  4. EAP-PEAP-MSCHAPv2

Answer(s): B


Reference:

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure- eap-tls-authentication-with-is.html



An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.
What must be configured to accomplish this task?

  1. dynamic access list within the authorization profile
  2. extended access-list on the switch for the client
  3. security group tag within the authorization policy
  4. port security on the switch based on the client’s information

Answer(s): A





Refer to the exhibit.
In which scenario does this switch configuration apply?

  1. when allowing a hub with multiple clients connected
  2. when allowing multiple IP phones to be connected
  3. when preventing users with hypervisor
  4. when bypassing IP phone authentication

Answer(s): A


Reference:

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/sec- user-8021x-xe-3se-5700-book/sec-ieee-802x-multi-auth.html





Refer to the exhibit.
Which switch configuration change will allow only one voice and one data endpoint on each port?

  1. auto to manual
  2. mab to dot1x
  3. multi-auth to multi-domain
  4. multi-auth to single-auth

Answer(s): C


Reference:

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/ configuration_guide/sec/b_166_sec_9300_cg/configuring_ieee_802_1x_port_based_authentication.html






Post your Comments and Discuss Cisco® 300-715 exam with other Community members:

Exam Discussions & Posts