300-208 Practice Questions
Prepare for 300-208 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 269 questions Locked
- 300-208Legacy Security Implementing Cisco Secure Access Solutions (SISAS) 205 questions Current
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 5
- Identity Management/Secure Access33%
- Threat Defense10%
- Troubleshooting, Monitoring and Reporting Tools7%
- Threat Defense Architectures17%
- Identity Management Architectures33%
- 1
A corporate laptop is attempting to authenticate via 802.1X using EAP-TLS. The authentication fails, and the ISE logs indicate a failure during the SSL handshake. Based on the diagram of the EAP-TLS flow, at which step does the client validate the ISE server's identity?
Show answer details
Correct answer: C
In the EAP-TLS flow, the server sends its certificate in the TLS Server Hello. The client must validate this certificate against its local trust store (Root CA). If the client does not trust the issuer of the ISE certificate, the handshake fails at this stage before the client sends its own certificate.
sequenceDiagram participant Client participant Switch participant ISE Client->>Switch: EAPOL-Start Switch->>Client: EAP-Request/Identity Client->>Switch: EAP-Response/Identity Switch->>ISE: RADIUS Access-Request ISE->>Switch: EAP-Request/TLS Start Switch->>Client: EAP-Request/TLS Start Client->>Switch: Client Hello Switch->>ISE: Client Hello ISE->>Switch: Server Hello, Certificate, Cert Request Switch->>Client: Server Hello, Certificate Note right of Client: Client Validates Server Cert Here Client->>Switch: Client Certificate - 2
When configuring a Redirect ACL on a Cisco Catalyst switch for Central Web Authentication (CWA), which traffic pattern must be explicitly denied to ensure the redirection process functions correctly?
Show answer details
Correct answer: C
In a Cisco Redirect ACL, 'deny' means 'do not redirect' (allow through normally), while 'permit' means 'intercept and redirect'. Essential traffic like DNS, DHCP, and traffic destined to the ISE portal itself (port 8443) must be denied (excluded from redirection) so the client can resolve the portal hostname and establish the session. If ISE traffic is permitted (redirected), the client enters a redirect loop.
- 3
A company uses MAC Authentication Bypass (MAB) for IP cameras. The goal is to dynamically assign these cameras to the 'PhysicalSecurity' VLAN based on their device profile. Which ISE policy construct is most appropriate for mapping the profiled device type to the specific authorization result?
Show answer details
Correct answer: C
ISE places profiled devices into Endpoint Identity Groups (e.g., 'IP-Cameras'). The most effective way to assign permissions is to create an Authorization Policy rule that uses the condition 'IdentityGroup:Name EQUALS IP-Cameras' and assigns the corresponding Authorization Profile containing the VLAN assignment.
- 4
When configuring the DHCP probe in Cisco ISE for profiling, which specific DHCP option provides the 'Class Identifier' that is most commonly used to identify device types like IP phones and printers?
Show answer details
Correct answer: A
DHCP Option 60 is the Vendor Class Identifier (VCI). Manufacturers configure this option to identify the hardware model or type (e.g., 'Cisco AP c1240'). ISE heavily relies on Option 60 for accurate profiling of infrastructure devices.
- 5
An organization requires that HR employees can create guest accounts but only for visitors located in the 'Lobby' location, and these accounts should only be valid for 8 hours. Which ISE Guest Services component is used to enforce these specific constraints on the HR employees?
Show answer details
Correct answer: B
Sponsor Groups define what a sponsor (the HR employee) can do. This includes which Guest Types they can create (controlling duration), which locations they manage, and what account details they can modify. Assigning HR to a specific Sponsor Group allows enforcement of these limits.
- 6
A network administrator needs to implement a service that enables granular control of IOS commands that can be executed. Which AAA authentication method should be selected? A.TACACS+B.RADIUSC.Windows Active DirectoryD.Generic LDAP
Show answer details
Correct answer: A
- 7
An administrator can leverage which attribute to assign privileges based on Microsoft Active Directory user groups? A.member ofB.groupC.classD.person
Show answer details
Correct answer: A
- 8
Cisco 802.1X phasing enables flexible deployments through the use of open, low-impact, and closed modes. What is a unique characteristic of the most secure mode? A.Granular ACLs applied prior to authenticationB.Per user dACLs applied after successful authenticationC.Only EAPoL traffic allowed prior to authenticationD.Adjustable 802.1X timers to enable successful authentication
Show answer details
Correct answer: C
