Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :404 Q&As
  • Last Updated
    :Mar 28, 2025

Cisco CCNP Security 300-715 Questions & Answers

  • Question 41:

    An administrator in a health facility must assign a medical device to a static profiling policy. Under which settings group must it be configured?

    A. user-defined exception actions

    B. CoA under global settings

    C. global profiling settings

    D. system-defined exceptions actions

  • Question 42:

    An engineer must configure guest access on Cisco ISE for company visitors. Which step must be taken on the Cisco ISE PSNs before a guest portal is configured?

    A. Install SSL certificates

    B. Create a node group

    C. Enable profiling services

    D. Enable session services

  • Question 43:

    A network engineer is configuring a portal on Cisco ISE for employees. Employees must use this portal when registering personal devices with native supplicants. For onboarding devices connected with Cisco switches and Cisco wireless LAN controllers, the internal CA must be used. Which portal type must the engineer configure?

    A. Personal Device portal

    B. Client Provisioning portal

    C. Bring Your Own Device portal

    D. My Devices portal

  • Question 44:

    An engineer must configure web redirection for guests to a portal where no authentication is required and an Acceptable Use Policy must be accepted by the guest before network access is allowed. Which type of guest portal must be configured in Cisco ISE to meet the requirement?

    A. Sponsored

    B. Self Registered

    C. Hotspot

    D. Custom

  • Question 45:

    A user recently had their laptop stolen. IT has ordered a replacement device for the user and was able to obtain the MAC address of the device 04.57:47:34 35 0A from the vendor before it shipped. Which statement regarding adding MAC addresses to Cisco ISE is correct?

    A. MAC addresses can only be manually imported using a .csv file and the import option.

    B. MAC addresses can only be manually imported using the REST API.

    C. MAC addresses can only be allowed after the device has connected to the network.

    D. MAC addresses can be manually added using the + sign under Context Visibility > Endpoints.

  • Question 46:

    Which two tasks must be completed when configuring the Cisco ISE BYOD Portal? (Choose two.)

    A. Enable policy services.

    B. Create endpoint identity groups.

    C. Customize device portal.

    D. Provision external identity sources.

    E. Deploy client provisioning portal.

  • Question 47:

    When configuring Active Directory groups, an administrator is attempting to retrieve a group that has a name that is ambiguous with another group. What must be done so that the correct group is returned?

    A. Use the SID as the identifier for the group.

    B. Configure MAB to utilize one group, and 802 1xto utilize the conflicting group.

    C. Select both groups, and use a TCT pointer to identity the appropriate one.

    D. Utilize MIB entries to identify the desired group.

  • Question 48:

    An administrator has manually added the MAC address of a wireless device to the Blocklist Identity Group for testing. When the device connects to the wireless network it triggers the Wireless Block List Default rule, but the device is still allowed to access the wireless network. What additional step must be taken to resolve tissue?

    A. Disable URL redirection on the Authorization Profile.

    B. Enable SNMP with read and write access on the Cisco WLC.

    C. Create an ACL named BLOCKHOLE on the Cisco WLC.

    D. Change the Access Type under the Authorization Profile lo ACCESS_REJECT.

  • Question 49:

    What is the difference between how RADIUS and TACACS+ handle encryption?

    A. RADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet.

    B. RADIUS only encrypts the password field, whereas TACACS+ encrypts the entire packet.

    C. RADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields.

    D. RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.

  • Question 50:

    Which CLI command must be configured on the switchport to immediately run the MAB process if a non-802 1X capable endpoint connects to the port?

    A. authentication order mab dot1x

    B. dot1x pae authenticator

    C. authentication fallback

    D. access-session port-control auto

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.