Courseiva

Cisco Implementing and Configuring Cisco Identity Services Engine (SISE, 300-715, CCNP Security) (SISE) (SISE) — Questions 301322

322 questions total · 5pages · All types, answers revealed

Page 4

Page 5 of 5

301
Multi-Selecteasy

Which TWO of the following are valid remediation actions available in Cisco ISE for posture compliance?

Select 2 answers
A.MAC Authentication Bypass
B.Link Remediation
C.VLAN Change
D.Downloadable ACL
E.File Remediation
AnswersB, E

Provides a URL to the user to download patches or software to fix compliance.

Why this answer

Cisco ISE supports various remediation actions including link-based (for web portals) and file-based actions to help users become compliant.

302
MCQhard

You are observing that an endpoint is being profiled as 'Unknown' even though it is clearly a Windows workstation. What is the most likely reason?

A.The device is using a static IP.
B.The necessary probes are not receiving enough attributes to match a policy.
C.The endpoint is not authenticated.
D.The endpoint has a firewall enabled.
AnswerB

Insufficient attributes mean no profile policy criteria are met.

Why this answer

If ISE has not received enough attributes to meet the threshold of a profiling policy, it remains 'Unknown'.

303
MCQeasy

Which license type is required to enable advanced profiling and posture services on Cisco ISE?

A.ISE Premier
B.Device Admin License
C.ISE Essentials
D.ISE Advantage
AnswerD

Advantage provides advanced profiling and posture capabilities.

Why this answer

ISE licenses are tiered, and 'ISE Advantage' is typically required for advanced context-aware features like profiling and posture.

304
MCQhard

A user is unable to pass posture assessment because the 'AnyConnect Compliance Module' is not detecting the antivirus software. Which log file on the endpoint should be reviewed to troubleshoot the compliance module's scanning logic?

A.NAC Agent Log (nac_agent.log)
B.Windows Event Viewer - Application Log
C.AnyConnect Compliance Module log (ac_ise_posture.log)
D.ISE Posture Log (ise_posture.log)
AnswerC

This is the primary log file on the Windows endpoint for troubleshooting compliance agent scan results.

Why this answer

The ACLog.txt or the Compliance Module logs (typically found in %ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture) contain details about scan results.

305
MCQeasy

Which of the following is a valid remediation action type in Cisco ISE?

A.Process Kill Remediation
B.Network Remediation
C.File Remediation
D.User Prompt Remediation
AnswerC

File remediation allows for local file execution or download.

Why this answer

File, Registry, and Service remediation are standard options.

306
MCQmedium

You are configuring a policy set for wireless guest access and need to ensure that the authorization policy only triggers if the user has successfully authenticated via the Guest portal. Which condition should you use?

A.Radius:Service-Type equals Framed
B.Session:AuthenticationStatus equals Guest
C.Device:DeviceType equals Wireless
D.Radius:Called-Station-ID
AnswerB

This condition verifies the session authentication status matches the guest state.

Why this answer

The 'Guest Type' or 'Guest Flow' attributes are specific to the Guest portal authentication process, ensuring the policy only applies after successful portal interaction.

307
Multi-Selectmedium

Which THREE of the following items must be configured to ensure a successful SNMP Trap profiling implementation?

Select 3 answers
A.Add the network switch to the ISE Network Devices list.
B.Enable the SNMP Trap probe on the ISE PSN.
C.Enable HTTP probe.
D.Configure the network switch to send SNMP traps to the ISE PSN.
E.Configure DHCP Snooping.
AnswersA, B, D

ISE needs the device in its inventory to process the traps.

Why this answer

SNMP traps require the network device to be configured to send traps, the ISE PSN to listen for them, and the correct trap community or user context.

308
Multi-Selectmedium

Which THREE of the following are found in an Authorization Profile's 'Advanced Attributes'?

Select 3 answers
A.Vendor Specific Attributes (VSAs)
B.Custom RADIUS attributes
C.Policy Set conditions
D.Device admin rules
E.Attribute name/value pairs
AnswersA, B, E

VSAs are managed in the advanced section.

Why this answer

Advanced attributes allow for custom RADIUS attributes and vendor-specific fields.

309
Multi-Selectmedium

Which THREE of the following are valid types of Client Provisioning Resources?

Select 3 answers
A.AnyConnect Profile (XML)
B.Windows Update Agent
C.Compliance Module
D.AnyConnect Core Package
E.Antivirus definition files
AnswersA, C, D

This is a required resource.

Why this answer

Valid resources include AnyConnect packages, compliance modules, and profiles.

310
MCQhard

You want to enforce a policy where personal devices are allowed access, but only if they are not jailbroken. How is this achieved in a BYOD scenario?

A.Use ISE profiling only
B.Use an ACL on the switch
C.Configure a WLC-based check
D.Integrate an MDM that performs jailbreak detection
AnswerD

MDM is the only component capable of deep device health checks like jailbreak detection.

Why this answer

MDM integration is required to perform health checks like jailbreak detection, which is then reported to ISE to inform the authorization decision.

311
MCQmedium

When adding a network device to ISE, you select the 'TACACS+ Authentication Settings' checkbox. What is the impact of this action?

A.It enables RADIUS for this device
B.It enables TACACS+ services for this device
C.It forces the switch to use SNMP
D.It automatically configures the switch via CLI
AnswerB

This is the prerequisite for TACACS+ processing.

Why this answer

Checking this box enables the device to participate in TACACS+ authentication and authorization flows managed by ISE.

312
Multi-Selectmedium

Which THREE of the following are valid ways to trigger a profiling scan or update for an endpoint in Cisco ISE?

Select 3 answers
A.Manually trigger 'Re-profile' in Context Visibility.
B.Receive a new probe update for the endpoint.
C.Change the device's IP address.
D.Send a Change of Authorization (CoA) from a policy rule.
E.Modify the endpoint's MAC address.
AnswersA, B, D

This forces the profiler to re-evaluate collected data.

Why this answer

Endpoints can be re-profiled via manual refresh, CoA events, or changes in probe data.

313
MCQmedium

A user is compliant, but ISE still classifies the device as 'Unknown'. What is the most likely cause?

A.The posture agent failed to connect to the PSN
B.The Client Provisioning policy is misconfigured
C.The remediation action is disabled
D.The authorization rule is incorrect
AnswerA

If the agent cannot send the report, ISE keeps the status as 'Unknown'.

Why this answer

If the device is 'Unknown', it means the posture agent has not successfully sent the report to the PSN or the PSN has not updated the session state.

314
Multi-Selecthard

Which TWO of the following steps are required to implement SGT-based enforcement using an SXP connection?

Select 2 answers
A.Apply a dACL to every port
B.Define the SGT mapping in the ISE TrustSec configuration
C.Enable TACACS+ on the NAD
D.Configure the SXP connection between the ISE node and the NAD
E.Enable 802.1X on all switch ports
AnswersB, D

The mapping of IP to SGT must be defined so ISE knows what to propagate.

Why this answer

SXP is used to propagate SGTs to devices that are not SGT-capable natively. This involves configuring the connection and ensuring the mapping is present.

315
MCQmedium

You are deploying a Posture agent using the Web Agent. Which mechanism does the Web Agent use to perform compliance checks on a Windows machine?

A.It performs deep packet inspection to determine compliance.
B.It requires the full AnyConnect VPN client to be pre-installed.
C.It communicates directly with the Microsoft Update server.
D.It relies on WMI calls initiated by the ISE server.
E.It uses a temporary ActiveX or Java component to scan the system.
AnswerE

The Web Agent relies on browser-based plugins or temporary executables to facilitate basic posture checks before full agent deployment.

Why this answer

The AnyConnect Web Agent (now referred to as the posture agent in browser-less scenarios or via the portal) uses a small temporary utility to gather information, but it is limited in scope compared to the persistent AnyConnect agent.

316
Multi-Selectmedium

Which THREE factors influence the decision to use multiple PSNs in a deployment?

Select 3 answers
A.Increased log storage capacity
B.Centralized database backup
C.Geographical distribution
D.Load balancing of RADIUS requests
E.Redundancy for node failure
AnswersC, D, E

Reduces latency for remote sites.

Why this answer

Multiple PSNs are used for geographical redundancy, load balancing of authentication requests, and high availability in case of node failure.

317
MCQmedium

Which of the following is a key requirement for dACL enforcement on a Cisco switch?

A.The switch must be in Layer 3 mode
B.The switch must be running in VTP Transparent mode
C.The switch must have 'aaa authorization auth-proxy' enabled
D.The switch must support RADIUS dynamic authorization
AnswerD

Dynamic Authorization is required to apply the dACL to the session post-auth.

Why this answer

The switch must be configured as a RADIUS client and the port must be enabled for 802.1X/MAB; the switch must support the 'dACL' feature.

318
MCQhard

You are troubleshooting a PSN that is not receiving configuration updates. Which log file on the PSN would provide the most insight into the configuration sync process?

A.config-dist.log
B.catalina.out
C.radius.log
D.prrt-server.log
AnswerA

This log traces the configuration distribution process.

Why this answer

The 'config-dist.log' file specifically tracks the configuration distribution and synchronization events between the PAN and PSN.

319
MCQmedium

When configuring a policy set, which attribute is most commonly used to distinguish between a Wired and Wireless request?

A.Framed-IP-Address
B.NAS-Port-Type
C.Calling-Station-ID
D.Device-Name
AnswerB

NAS-Port-Type indicates if the request is wired or wireless.

Why this answer

The 'NAS-Port-Type' attribute is standard for identifying the access medium (e.g., Wireless-802.11 vs. Ethernet).

320
Multi-Selectmedium

Which THREE of the following are valid methods for collecting endpoint attributes for profiling in Cisco ISE?

Select 3 answers
A.FTP inspection
B.SSH terminal login
C.HTTP User-Agent
D.DHCP Snooping/Helper
E.SNMP Query
AnswersC, D, E

HTTP probe collects browser information.

Why this answer

The probes that gather data include DHCP, SNMP, and HTTP.

321
MCQeasy

In the ISE Policy Set, which component is used to define the user credentials' verification method?

A.Policy Set Condition
B.Authentication Policy
C.Result Profile
D.Authorization Policy
AnswerB

The Authentication Policy defines the allowed protocols and identity sources.

Why this answer

The Authentication Policy defines the Identity Source Sequence, which dictates how ISE verifies credentials.

322
Multi-Selecthard

When setting up TACACS+ for network administration, which THREE configurations must be present on the Cisco network device? (Choose three)

Select 3 answers
A.AAA authentication/authorization commands
B.Local user database for all commands
C.RADIUS server configuration
D.Shared secret matching the ISE configuration
E.TACACS+ server group configuration
AnswersA, D, E

This enables the AAA framework.

Why this answer

The switch needs the TACACS+ server IP, the shared secret, and the AAA command authorization configured.

Page 4

Page 5 of 5

All pages