Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Cisco > CCNP Security > 300-715 > 300-715 Online Practice Questions and Answers

300-715 Online Practice Questions and Answers

Questions 4

Which interface-level command is needed to turn on 802.1X authentication?

A. dot1x pae authenticator

B. dot1x system-auth-control

C. authentication host-mode single-host

D. aaa server radius dynamic-author

Buy Now

Correct Answer: A

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sg/configuration/guide/conf/dot1x.html

Questions 5

Which two endpoint compliance statuses are possible? (Choose two.)

A. unknown

B. known

C. invalid

D. compliant

E. valid

Buy Now

Correct Answer: AD

Questions 6

An engineer is configuring cisco ISE and need to dynamically identify the network endpoints and ensure that endpoint access is protected. Which service should be used to accomplish this task?

A. Guest access

B. Profiling

C. Posture

D. Client provisioning

Buy Now

Correct Answer: C

Questions 7

A network security engineer needs to configure 802.1X port authentication to allow a single host to be authenticated for data and another single host to be authenticated for voice. Which command should the engineer run on the interface to accomplish this goal?

A. authentication host-mode single-host

B. authentication host-mode multi-auth

C. authentication host-mode multi-host

D. authentication host-mode multi-domain

Buy Now

Correct Answer: D

Questions 8

An employee logs on to the My Devices portal and marks a currently on-boarded device as `Lost'.

A. Certificates provisioned to the device are not revoked

B. BYOD Registration status is updated to No

C. The device access has been denied

D. BYOD Registration status is updated to Unknown.

E. The device status is updated to Stolen

Buy Now

Correct Answer: AC

https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01111.html

Questions 9

An engineer tests Cisco ISE posture services on the network and must configure the compliance module to automatically download and install on endpoints. Which action accomplishes this task for VPN users?

A. Push the compliance module from Cisco FTD prior to attempting posture.

B. Use a compound posture condition to check for the compliance module and download, if needed.

C. Configure the compliance module to be downloaded from within the posture policy.

D. Create a Cisco AnyConnect configuration and Client Provisioning policy within Cisco ISE.

Buy Now

Correct Answer: D

Reference: https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_configure_client_provisioning.html

Questions 10

An engineer is configuring ISE for network device administration and has devices that support both protocols.

What are two benefits of choosing TACACS+ over RADUs for these devices? (Choose two.)

A. TACACS+ is FIPS compliant while RADIUS is not

B. TACACS+ is designed for network access control while RADIUS is designed for role-based access.

C. TACACS+ uses secure EAP-TLS while RADIUS does not.

D. TACACS+ provides the ability to authorize specific commands while RADIUS does not

E. TACACS+ encrypts the entire payload being sent while RADIUS only encrypts the password.

Buy Now

Correct Answer: DE

Questions 11

What is a difference between TACACS+ and RADIUS in regards to encryption?

A. TACACS+ encrypts only the password, whereas RADIUS encrypts the username and password.

B. TACACS+ encrypts the username and password, whereas RADIUS encrypts only the password.

C. TACACS+ encrypts the password, whereas RADIUS sends the entire packet in clear text.

D. TACACS+ encrypts the entire packet, whereas RADIUS encrypts only the password.

Buy Now

Correct Answer: D

Reference: https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13838-10.html

Questions 12

A Cisco ISE administrator is setting up Central Web Authentication to be used for user endpoint authentication. The client cannot reach the guest portal to log in and gain access, but DNS is functioning properly and the guest portal is enabled. What else must be configured to gain access?

A. Allow port TCP/8443 on the firewall.

B. Configure HTTP to HTTPS redirection.

C. Configure the guest portal to listen on TCP/8443.

D. Allow redirection from any client IP range.

Buy Now

Correct Answer: A

Questions 13

What is configured to enforce the blocklist permissions and deny access to clients in the blocklist to protect against a lost or stolen device obtaining access to the network?

A. My Devices portal

B. blocklist portal

C. Authentication rule

D. Authorization rule

Buy Now

Correct Answer: D

Exam Code: 300-715
Exam Name: Implementing and Configuring Cisco Identity Services Engine (SISE)
Last Update: Jun 07, 2025
Questions: 404

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2025 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.