Exam Details

  • Exam Code
    :300-715
  • Exam Name
    :Implementing and Configuring Cisco Identity Services Engine (SISE)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :404 Q&As
  • Last Updated
    :Mar 28, 2025

Cisco CCNP Security 300-715 Questions & Answers

  • Question 51:

    The security engineer for a company has recently deployed Cisco ISE to perform centralized authentication of all network device logins using TACACSs+ against the local AD domain. Some of the other network engineers are having a hard time remembering to enter their AD account password instead of the local admin password that they have used for years. The security engineer wants to change the password prompt to "Use Local AD Password:" as a way of providing a hint to the network engineers when logging in. Under which page in Cisco ISE would this change be made?

    A. Work Centers> Device Administration Ext Id Sources>Advanced Settings

    B. The password prompt cannot be changed on a Cisco IOS device

    C. Work Centers> Device Administration> Network Resources> Network Devices

    D. Work Centers> Device Administration> Settings> Connection Settings

  • Question 52:

    The 300 GB OVA templates for VMs are sufficient for which two dedicated Cisco ISE node types? (Choose two.)

    A. Administration

    B. Log Collector

    C. pxGrid

    D. Policy Service

    E. Monitoring

  • Question 53:

    A network engineer has recently configured a remote branch router to authenticate to a centralized Cisco ISE server behind the corporate firewall using TACACS+. After making this configuration change, the engineer opened another SSH session to the router in order to verity that login attempts are now being sent to Cisco ISE, however that login attempt was unsuccessful. There are no connection attempts showing in the TACACS live log in Cisco ISE and the firewall administrator has verified that they see syslog and SNMP traffic destinated for the IP address of Cisco ISE, but no TACACS+ traffic. Which misconfiguration is the cause of the failed login?

    A. The router is missing a route to the Cisco ISE server.

    B. The tacacs source-interface command on the router references the wrong interface.

    C. No hosts have been defined under the aaa server group on the router.

    D. The shared secret entered on the router for the Cisco ISE server is incorrect.

  • Question 54:

    An engineer is configuring a new switch to deploy in the campus network. The task is to configure TACACS+ and RADIUS authentication using the new switch and Cisco ISE. What is the procedure for adding this new switch on the network resources page?

    A. network devices profiles > add

    B. default device > add

    C. network devices > add

    D. network devices groups > add

  • Question 55:

    A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.)

    A. switch ID

    B. MAC address

    C. VLAN

    D. user ID

    E. interface

  • Question 56:

    A new Cisco ISE infrastructure is being built to provide network access control. If Cisco Discovery Protocol is used, what information is being gathered in relation to profiling with Cisco ISE?

    A. IdentityGroup

    B. device ID

    C. RADIUS session attributes

    D. DHCP session attributes

  • Question 57:

    A customer requires a Cisco ISE deployment where quests must log in to a webpage with unique credentials in the form username. User1 and Password: A463646808. Which deployment should the customer use?

    A. mobile number field using the guest page

    B. hotspot portal authentication

    C. single credentials login to guest portal

    D. captcha protection self-registration

  • Question 58:

    Which Cisco ISE module contains a list of vendor names, product names, and attributes provided by OPSWAT?

    A. Compliance Module

    B. Client Provisioning Module

    C. Endpoint Security Module

    D. Posture Module

  • Question 59:

    An administrator is configuring posture assessment in Cisco ISE for the first time. Which two components must be uploaded to Cisco ISE to use Anyconnect for the agent configuration in a client provisioning policy? (Choose two.)

    A. Anyconnect network visibility module

    B. Anyconnect compliance module

    C. AnyConnectProfile.xml file

    D. AnyConnectProfile.xsd file

    E. Anyconnect agent image

  • Question 60:

    Which two statements are correct regarding the differences between RADIUS and TACACS+? (Choose two.)

    A. RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.

    B. RADIUS primary use is for network access, whereas TACACS+ primary use is for device administration.

    C. RADIUS combines the authentication and authorization functions, whereas TACACS+ separates them.

    D. RADIUS uses TCP as the transmission protocol, whereas TACACS+ uses both UDP and TCP protocols.

    E. RADIUS supports full command logging, whereas TACACS+ does not provide any command logging.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.