Free 300-715 Exam Braindumps (page: 20)

Page 19 of 93

What is an advantage of using EAP-TLS over EAP-MS-CHAPv2 for client authentication?

  1. EAP-TLS uses a username and password for authentication to enhance security, while EAP-MS-CHAPv2 does not.
  2. EAP-TLS uses multiple forms of authentication, while EAP-MS-CHAPv2 only uses one.
  3. EAP-TLS uses a device certificate for authentication to enhance security, while EAP-MS-CHAPv2 does not.
  4. EAP-TLS secures the exchange of credentials, while EAP-MS-CHAPv2 does not.

Answer(s): C


Reference:

https://www.securew2.com/blog/eap-tls-vs-peap-mschapv2-which-authentication-protocol-is- superior



What must be configured on the WLC to configure Central Web Authentication using Cisco ISE and a WLC?

  1. Use the ip access-group webauth in command.
  2. Use the radius-server vsa send authentication command.
  3. Set the NAC State option to SNMP NA
  4. Set the NAC State option to RADIUS NAC.

Answer(s): D


Reference:

https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/ b_cg76_chapter_0110001.pdf



A network administrator is configuring authorization policies in Cisco ISE. There is a requirement to use AD group assignments to control access to network resources. After a recent power failure and Cisco ISE rebooting itself, the AD group assignments no longer work.
What is the cause of this issue?

  1. The AD join point is no longer connected.
  2. The certificate checks are not being conducted.
  3. The network devices ports are shut down.
  4. The AD DNS response time is slow.

Answer(s): A


Reference:

https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/ise_active_directory_integration/ b_ISE_AD_integration_2x.html#ID612





Refer to the exhibit.
Which component must be configured to apply the SGACL?

  1. secure server
  2. host
  3. egress router
  4. ingress router

Answer(s): C


Reference:

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SY/configuration/guide/ sy_swcg/trustsec.pdf






Post your Comments and Discuss Cisco® 300-715 exam with other Community members:

Exam Discussions & Posts