Free 350-701 Exam Braindumps (page: 23)

Page 23 of 153

An engineer must force an endpoint to re-authenticate an already authenticated session without disrupting the endpoint to apply a new or updated policy from ISE.
Which CoA type achieves this goal?

  1. Port Bounce
  2. CoA Terminate
  3. CoA Reauth
  4. CoA Session Query

Answer(s): C



Which two probes are configured to gather attributes of connected endpoints using Cisco Identity Services
Engine? (Choose two)

  1. RADIUS
  2. TACACS+
  3. DHCP
  4. sFlow
  5. SMTP

Answer(s): A,C



Which ID store requires that a shadow user be created on Cisco ISE for the admin login to work?

  1. RSA SecureID
  2. Internal Database
  3. Active Directory
  4. LDAP

Answer(s): C



An engineer used a posture check on a Microsoft Windows endpoint and discovered that the MS17- 010 patch was not installed, which left the endpoint vulnerable to WannaCry ransomware.
Which two solutions mitigate the risk of this ransom ware infection? (Choose two)

  1. Configure a posture policy in Cisco Identity Services Engine to install the MS17-010 patch before allowing access on the network.
  2. Set up a profiling policy in Cisco Identity Service Engine to check and endpoint patch level before allowing access on the network.
  3. Configure a posture policy in Cisco Identity Services Engine to check that an endpoint patch level is met before allowing access on the network.
  4. Configure endpoint firewall policies to stop the exploit traffic from being allowed to run and replicate throughout the network.
  5. Set up a well-defined endpoint patching strategy to ensure that endpoints have critical vulnerabilities patched in a timely fashion.

Answer(s): A,C

Explanation:

A posture policy is a collection of posture requirements, which are associated with one or more identity groups, and operating systems. We can configure ISE to check for the Windows patch at Work Centers > Posture > Posture Elements > Conditions > File. In this example, we are going to use the predefined file check to ensure that our Windows 10 clients have the critical security patch installed to prevent the Wanna Cry malware.



Page 23 of 153



Post your Comments and Discuss Cisco® 350-701 exam with other Community members:

David A commented on January 16, 2024
Good Colombia
Anonymous
upvote

Kim commented on May 25, 2023
I just purchased and downloaded my files. Everything looks good so far.
UNITED STATES
upvote