300-715 Implementing and Configuring Cisco Identity Services Engine (SISE) Practice Questions
Prepare for 300-715 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 269 questions Current
- 300-208Legacy Security Implementing Cisco Secure Access Solutions (SISAS) 205 questions Locked
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 7
- Architecture and Deployment10%
- Policy Enforcement25%
- Web Auth and Guest Services15%
- Profiler15%
- BYOD15%
- Endpoint Compliance10%
- Network Access Device Administration10%
- 1
A Senior Network Security Architect is designing a TACACS+ Command Set for a team of junior operators at a logistics company. The requirement allows these operators to view interface configurations but strictly prohibits them from viewing the running configuration of the device itself to protect shared secrets. Which Command Set configuration strategy efficiently achieves this while adhering to the principle of least privilege?
Show answer details
Correct answer: A
To allow viewing specific interface configurations (e.g., 'show running-config interface GigabitEthernet1/0/1') while blocking the global 'show running-config', you must use a regular expression. The command 'show running-config interface.*' permits commands that start with that string, while a separate deny (or implicit deny) blocks the bare 'show running-config'.
- 2
An administrator is configuring a 'Self-Registered Guest Portal' for a corporate campus. The goal is to allow guests to register devices for 24 hours, but a sponsor must approve the account before network access is granted. After 24 hours, the account should automatically purge. Which combination of settings in the Guest Portal configuration is required to support this workflow?
Show answer details
Correct answer: A
In the Self-Registered Guest Portal settings, checking 'Require self-registered guests to be approved' enforces the workflow. The Guest Type determines the duration (24 hours), and the approval email is sent to members of the configured Sponsor Group.
- 3
A manufacturing firm uses Cisco ISE to profile IoT devices. The network team notices that while 'printer' devices are correctly identified, they often flip between 'printer' and 'Xerox-device' profiles, causing frequent re-authentications. What configuration change in the Profiler settings would stabilize this behavior?
Show answer details
Correct answer: A
Profile flapping occurs when multiple profiles have similar certainty factors and incoming attributes cause the endpoint to match one then the other. Increasing the Certainty Factor for the more specific profile (Xerox-device) ensures it remains the dominant profile once matched, preventing regression to the generic profile.
- 4
When configuring a Client Provisioning Policy for Windows endpoints, an administrator needs to ensure that only corporate assets running Windows 10 or later receive the AnyConnect Posture Module. All other Windows devices should receive the Temporal Agent. Which condition should be used to differentiate these assets reliably?
Show answer details
Correct answer: A
To differentiate 'corporate assets' from other devices, Active Directory group membership (like 'Domain Computers') is the most reliable condition available during the Client Provisioning phase. OS version alone (Windows 10) would match personal devices as well.
- 5
A security consultant is implementing a BYOD flow where employees must register their personal iPads. The organization requires that the device's UDID be registered in the endpoint database to limit each user to 2 devices. Which ISE portal type is specifically designed to extract this hardware identifier during the onboarding process via an OTA (Over-the-Air) profile?
Show answer details
Correct answer: A
The BYOD Portal (used in the Native Supplicant Provisioning flow) installs an OTA profile on iOS devices. This process allows ISE to query the device for its Unique Device Identifier (UDID) and register it in the My Devices endpoint group, enforcing device limits.
- 6
Which personas can a Cisco ISE node assume?
Show answer details
Correct answer: C
- 7
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?
Show answer details
Correct answer: A
- 8
Which two features are available when the primary admin node is down and the secondary admin node has not been promoted? (Choose two.)
Show answer details
Correct answer: A, C
