Which CLI command must be configured on the switchport to immediately run the MAB process if a non-802 1X capable endpoint connects to the port?
Aauthentication order mab dot1x
Bdot1x pae authenticator
Cauthentication fallback
Daccess-session port-control auto
The 300 GB OVA templates for VMs are sufficient for which two dedicated Cisco ISE node types? (Choose two.)
AAdministration
BLog Collector
CpxGrid
DPolicy Service
EMonitoring
A network engineer has recently configured a remote branch router to authenticate to a centralized Cisco ISE server behind the corporate firewall using TACACS+. After making this configuration change, the engineer opened another SSH session to the router in order to verity that login attempts are now being sent to Cisco ISE, however that login attempt was unsuccessful. There are no connection attempts showing in the TACACS live log in Cisco ISE and the firewall administrator has verified that they see syslog and SNMP traffic destinated for the IP address of Cisco ISE, but no TACACS+ traffic. Which misconfiguration is the cause of the failed login?
AThe router is missing a route to the Cisco ISE server.
BThe tacacs source-interface command on the router references the wrong interface.
CNo hosts have been defined under the aaa server group on the router.
DThe shared secret entered on the router for the Cisco ISE server is incorrect.
Which two tasks must be completed when configuring the Cisco ISE BYOD Portal? (Choose two.)
AEnable policy services.
BCreate endpoint identity groups.
CCustomize device portal.
DProvision external identity sources.
EDeploy client provisioning portal.
Question 6
Endpoint Compliance
0
Question 7
Endpoint Compliance
Question 8
Architecture and Deployment
Question 9
Profiler
Question 10
Profiler
Question 11
Network Access Device Administration
Question 12
Profiler
Question 13
Web Auth and Guest Services
Question 14
Architecture and Deployment
Question 15
Network Access Device Administration
Question 16
BYOD
Question 17
Network Access Device Administration
Question 18
Web Auth and Guest Services
Question 19
Web Auth and Guest Services
Question 20
Policy Enforcement
Question 21
Network Access Device Administration
Question 22
Network Access Device Administration
Question 23
Network Access Device Administration
Question 24
Policy Enforcement
Question 25
Network Access Device Administration
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
An administrator is configuring posture assessment in Cisco ISE for the first time. Which two components must be uploaded to Cisco ISE to use Secure Client for the agent configuration in a client provisioning policy? (Choose two.)
ASecureClientProtie.xsd file
BSecure Client compliance module
CSecure Client agent image
DSecureClientProfie.xml file
ESecure Client network visibility module
An engineer configured posture assessment for their network access control with the goal of using an agent that supports using service conditions for the assessment. The agent should run as a background process to avoid user interruption, but the user can see it when it is run. What is the problem?
AThe selected posture agent does not support the engineer's goal.
BThe posture module was deployed using the headend instead of installing it with SCCM.
CThe proper permissions were not given to the temporal agent to conduct the assessment.
DThe user required remediation so the agent appeared in the notifications.
An engineer is deploying Cisco ISE to use 802.1X authentication for controlling access to the company's wired network. The request from company management is to minimize the impact on users during the rollout of 802.1X on the company switches. Which mode must be used first in a phased 802.1X deployment to fulfill this request?
AMonitor
BOpen
CLow-impact
DClosed
An engineer must configure an HTTP probe on a Cisco ISE virtual appliance running on VMWare using a dedicated interface for profiling. The interface is assigned to the VM Network port group. The engineer is logged into the hypervisor with a user account that only provides access to the Cisco ISE VM and the network settings for the VM. Which security setting must be changed for this interface to accept SPAN traffic?
ASet Promiscuous mode to inherit from vSwitch in the Port Group properties.
BSet Promiscuous mode to inherit from Port Group in the vSwitch properties.
CSet Promiscuous mode to Accept in the Port Group properties.
DSet Promiscuous mode to Accept in the vSwitch properties.
An administrator is configuring MAB and needs to create profiling policies to support devices that do not match the built-in profiles. Which two steps must the administrator take in order to use these new profiles in authorization policies? (Choose two.)
AEdit the authorization policy to give the profiles as a result of the authentication and authorization results
BUse the profiling policies as the matching conditions in each authorization policy
CModify the endpoint identity group to feed the profiling policies into and match the parent group in the policy
DConfigure the profiling policy to make a matching identity group and use the group in the authorization policy
EFeed the profiling policies into a logical profile and use the logical profile in the authorization policy
A network engineer responsible for the switching environment must provision a new switch to properly propagate security group tags within the TrustSec inline method. Which CLI command must the network engineer enter on the switch to globally enable the tagging of SGTs?
Acts sxp enable
Bcts manual
Ccts role-based sgt-map
Dcts role-based enforcement
An administrator is configuring endpoint profiling and needs to enable CoA for devices that change profiles. Which two actions must be taken to accomplish this goal? (Choose two.)
AEnsure that the firewall is not blocking port 1700
BDefine "reauth" in the default CoA action to be used
CUse an API to detect when profile changes occur and send instructions to ISE to provide a CoA
DModify the RADIUS endpoint attribute filters to send CoA actions as the profiles change
EEnable the CoA policy and create rules for each type
A Cisco ISE administrator is setting up Central Web Authentication to be used for user endpoint authentication. The client cannot reach the guest portal to log in and gain access, but DNS is functioning properly and the guest portal is enabled. What else must be configured to gain access?
AAllow port TCP/8443 on the firewall.
BConfigure HTTP to HTTPS redirection.
CConfigure the guest portal to listen on TCP/8443.
DAllow redirection from any client IP range.
An administrator is configuring an AD domain to be used with authentication for endpoints and users within Cisco ISE. Which two steps are required to configure this to be used as an external identity store? (Choose two.)
AAdd an Authentication Joint Point.
BConfigure Authentication Domains.
CConfigure Active Directory Schema.
DConfigure Active Directory Domains.
EAdd an Active Directory Join Point.
A network engineer is attempting to terminate and reinitialize wireless user sessions individually by using the Live Sessions tab in Cisco ISE. Cisco ISE and the Cisco WLC are separated by a firewall. Which port must be allowed on the firewall so that the network engineer can perform this function from Cisco ISE?
ATCP port 8443
BUDP port 5246
CUDP port 1700
DTCP port 3791
A network engineer is configuring a new certificate template on the internal CA within Cisco ISE to provision certificates to BYOD devices that must be enrolled in the network. What must be configured in the SAN field of the certificate to identify the devices after enrollment?
AMAC address
Bemail address
Cuser principal name
Dcommon name
An engineer is configuring a new Cisco ISE node. The Device Admin service must run on this node to handle authentication requests for network device access via TACACS+. Which persona must be enabled on this node to perform this function?
ApxGrid
BAdministration
CPolicy Service
DMonitoring
An engineer has been tasked with using Cisco ISE to restrict network access at the switchport level using 802.1X authentication. Users who fail 802.1X authentication should e redirected via web redirection and have their access restricted via an ACL. What must be configured in Cisco ISE to accomplish this task?
Aan authorization profile
Ban authorization rule
Can authentication policy
Dan authentication profile
An engineer needs to create a Self-Registered Guest Portal in Cisco ISE in which guest users receive their passwords via SMS. Which two settings must be configured to accomplish this task? (Choose two.)
AChoose the SMS provider previously configured as a SMS gateway under the Registration Form Settings.
BSelect SMS for the Send Credential upon notification setting under Registration Form Settings.
CChoose the SMS provider previously configured as a SMS gateway under Device Registration Settings.
DSelect Allow employees to use personal devices and SMS for notifications under BYOD.
ESelect SMS for the Send Credential upon notification setting under the Login Page Settings.
A client connects to a network and the authenticator device learns the MAC address 04:49:23:86:34:AB of this client. After the MAC address is learned, the 802.1 x authentication process begins on this port. Which ISE deployment mode restricts all traffic initially, applies a rule for access control if 802.1x authentication is successful, and can be configured to grant only limited access if 802.1 x authentication is unsuccessful?
Aopen mode
Bmonitor mode
Cclosed mode
Dlow-impact mode
Which two statements are correct regarding the differences between RADIUS and TACACS+? (Choose two.)
ARADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.
BRADIUS primary use is for network access, whereas TACACS+ primary use is for device administration.
CRADIUS combines the authentication and authorization functions, whereas TACACS+ separates them.
DRADIUS uses TCP as the transmission protocol, whereas TACACS+ uses both UDP and TCP protocols.
ERADIUS supports full command logging, whereas TACACS+ does not provide any command logging.
What is the difference between how RADIUS and TACACS+ handle encryption?
ARADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet.
BRADIUS only encrypts the password field, whereas TACACS+ encrypts the entire packet.
CRADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields.
DRADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.
The security engineer for a company has recently deployed Cisco ISE to perform centralized authentication of all network device logins using TACACSs+ against the local AD domain. Some of the other network engineers are having a hard time remembering to enter their AD account password instead of the local admin password that they have used for years. The security engineer wants to change the password prompt to “Use Local AD Password:” as a way of providing a hint to the network engineers when logging in. Under which page in Cisco ISE would this change be made?
AWork Centers> Device Administration Ext Id Sources>Advanced Settings
BThe password prompt cannot be changed on a Cisco IOS device
An organization has a SGACL locally configured on a switch port, but when a user in the Executives group connects to the network, they receive a different level of network access than expected. When Cisco ISE pushes SGACLs to the switch after the authorization phase, how does the switch decide which access to grant the user?
ADynamically downloaded policies override local policies in all cases.
BLocal policies override dynamically downloaded policies in all cases.
CThe policies are merged, but local policies receive priority.
DThe policies are merged, but dynamically downloaded policies receive priority.
An administrator must enable scanning for specific endpoints when they attempt to access the network. The scanning must be triggered as a result of successful authentication. Which action accomplishes this task?
AModify the authorization policy to send init_endpoint_scan as a result to the authenticator.
BCreate an authorization profile with scanning enabled and add it to the authorization policy that the endpoints will hit.
CAdd an entry in the authentication conditions to allow only scanned endpoints access, then redirect everything else to the portal to initiate the scan.
DConfigure the endpoint scanning probe to profile the endpoint correctly and assign it a risk score.