Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :404 Q&As
  • Last Updated
    :Apr 14, 2025

Cisco CCNP Security 300-715 Questions & Answers

  • Question 251:

    A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA configuration must be used?

    A. port bounce

    B. no CoA

    C. exception

    D. reauth

  • Question 252:

    An engineer is configuring web authentication using non-standard ports and needs the switch to redirect traffic to the correct port. Which command should be used to accomplish this task?

    A. permit tcp any any eq

    B. aaa group server radius proxy

    C. IP http port

    D. aaa group server radius

  • Question 253:

    An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types. Which probe should be used to accomplish this task?

    A. MMAP

    B. DNS

    C. DHCP

    D. RADIUS

  • Question 254:

    In a standalone Cisco ISE deployment, which two personas are configured on a node? (Choose two.)

    A. publisher

    B. administration

    C. primary

    D. policy service

    E. subscriber

  • Question 255:

    An engineer must create an authentication policy in Cisco ISE to allow wired printers that lack support for 802.1X onto the network. What must the RadiusFlowType be set to in the policy to meet the requirement?

    A. MAB

    B. Wired_MAB

    C. Compliant_Devices

    D. Compliance_Unknown_Devices

  • Question 256:

    Which file extension is required when deploying Cisco ISE using a ZTP configuration file in Microsoft Hyper-V?

    A. .txt

    B. .img

    C. .tar

    D. .iso

  • Question 257:

    An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?

    A. monitor-mode enabled

    B. authentication host-mode multi-auth

    C. authentication open

    D. pae dot1x enabled

  • Question 258:

    An engineer wants to preselect AD groups to be used in the access policy after integrating Cisco ISE with an active directory. Which configuration steps must the engineer take to assign groups to the AD on the identity management page?

    A. external identity sources > active directory > groups

    B. user identity groups > groups

    C. external identity sources > groups > active directory

    D. groups > user identity groups

  • Question 259:

    An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?

    A. Use a third-party certificate on the network device.

    B. Add the device to all PSN nodes in the deployment.

    C. Configure an authorization profile for the end users.

    D. Renew the expired certificate on one of the PSN.

  • Question 260:

    An engineer must develop a policy that utilizes AD group membership on Cisco ISE. Which type of policy element must the engineer configure to create an AD group within a policy?

    A. conditions

    B. results

    C. dictionaries

    D. smart conditions

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.