Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :404 Q&As
  • Last Updated
    :Apr 14, 2025

Cisco CCNP Security 300-715 Questions & Answers

  • Question 181:

    A laptop was stolen and a network engineer added it to the block list endpoint identity group

    What must be done on a new Cisco ISE deployment to redirect the laptop and restrict access?

    A. Select DenyAccess within the authorization policy.

    B. Ensure that access to port 8443 is allowed within the ACL.

    C. Ensure that access to port 8444 is allowed within the ACL.

    D. Select DROP under If Auth fail within the authentication policy.

  • Question 182:

    An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?

    A. HTTP probe

    B. NetFlow probe

    C. network scan probe

    D. RADIUS probe

  • Question 183:

    What does a fully distributed Cisco ISE deployment include?

    A. PAN and PSN on the same node while MnTs are on their own dedicated nodes.

    B. PAN and MnT on the same node while PSNs are on their own dedicated nodes.

    C. All Cisco ISE personas on their own dedicated nodes.

    D. All Cisco ISE personas are sharing the same node.

  • Question 184:

    An administrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs. Besides defining a new shell profile in Cisco ISE.

    What must be done to accomplish this configuration?

    A. Enable the privilege levels in Cisco ISE

    B. Enable the privilege levels in the IOS devices.

    C. Define the command privileges for levels 2-5 in the IOS devices

    D. Define the command privileges for levels 2-5 in Cisco ISE

  • Question 185:

    An organization is adding new profiling probes to the system to improve profiling on Oseo ISE The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected

    What must be configured on the network device to accomplish this goal?

    A. ARP

    B. SNMP

    C. WCCP

    D. ICMP

  • Question 186:

    An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the used to accomplish this task?

    A. policy service

    B. monitoring

    C. pxGrid

    D. primary policy administrator

  • Question 187:

    An organization is migrating its current guest network to Cisco ISE and has 1000 guest users in the current database There are no resources to enter this information into the Cisco ISE database manually. What must be done to accomplish this task effciently?

    A. Use a CSV file to import the guest accounts

    B. Use SOL to link me existing database to Ctsco ISE

    C. Use a JSON fie to automate the migration of guest accounts

    D. Use an XML file to change the existing format to match that of Cisco ISE

  • Question 188:

    MacOS users are complaining about having to read through wordy instructions when remediating their workstations to gam access to the network Which alternate method should be used to tell users how to remediate?

    A. URL link

    B. message text

    C. executable

    D. file distribution

  • Question 189:

    A network administrator is configuring a secondary cisco ISE node from the backup configuration of the primary cisco ISE node to create a high availability pair The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE

    Which command most be issued for this to work?

    A. copy certificate Ise

    B. application configure Ise

    C. certificate configure Ise

    D. Import certificate Ise

  • Question 190:

    A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

    A. Port Bounce

    B. Reauth

    C. NoCoA

    D. Disconnect

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.