cisco 300-715 Exam Questions

Questions for the 300-715 were updated on : Dec 25 ,2025

Page 1 out of 21. Viewing questions 1-15 out of 306

Question 1

What is the difference between how RADIUS and TACACS+ handle encryption?

  • A. RADIUS encrypts the entire packet, whereas TACACS+ encrypts only the username and password fields.
  • B. RADIUS encrypts the entire packet, whereas TACACS+ only encrypts the password field.
  • C. RADIUS only encrypts the password field, whereas TACACS+ encrypts the payload of the packet.
  • D. RADIUS encrypts only the username and password fields, whereas TACACS+ encrypts the entire packet.
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

A user misplaces a personal phone and wants to blacklist the device from accessing the company
network. The company uses Cisco ISE for corporate and BYOD device authentication. Which action
must the user take in Cisco ISE?

  • A. Sign in to the BYOD portal and mark the device as Lost.
  • B. Sign in to the My Devices portal and mark the device as Lost.
  • C. Sign in to the My Devices portal and mark the device as Irrecoverable.
  • D. Sign in to the BYOD portal and mark the device as Irrecoverable.
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Which platform does a Windows-based device download the Network Assistant Manager from?

  • A. Microsoft app store
  • B. Cisco Catalyst Switch
  • C. native OS
  • D. Cisco ISE
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

The security engineer for a company has recently deployed Cisco ISE to perform centralized
authentication of all network device logins using TACACS+ against the local AD domain. Some of the
other network engineers are having a hard time remembering to enter their AD account password
instead of the local admin password that they have used for years. The security engineer wants to
change the password prompt to "Use Local AD Password:" as a way of providing a hint to the
network engineers when logging in. Under which page in Cisco ISE would this change be made?

  • A. Work Centers > Device Administration > Settings > Connection Settings
  • B. Work Centers > Device Administration > Ext Id Sources > Advanced Settings
  • C. The password prompt cannot be changed on a Cisco IOS device
  • D. Work Centers > Device Administration > Network Resources > Network Devices
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

An administrator must provide network access to legacy Windows endpoints with a specific device
type and operating system version using Cisco ISE profiler services. The ISE profiler services and
access switches must be configured to identify endpoints using the dhcp-class-identifier and
parameters-request-list attributes from the DHCP traffic. These configurations were performed:
enabled the DHCP probe in Cisco ISE
configured the Cisco ISE PSN interface to receive DHCP packets
configured the attributes in custom profiling conditions
configured a custom profiling policy
configured an authorization rule with permit access
Which action completes the configuration?

  • A. Configure the switches to send copies of the DHCP traffic to the Cisco ISE PSN.
  • B. Configure the Cisco ISE PSN interface to receive SPAN DHCP traffic.
  • C. Configure the switches to relay DHCP packets to the Cisco ISE PSN.
  • D. Enable the DHCP SPAN probe in Cisco ISE primary server.
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

A Cisco ISE administrator must authenticate users against Microsoft Active Directory. The solution
must meet these requirements:
Users and computers must be authenticated.
User groups must be retrieved during authentication.
Which protocol must be added to the allowed protocols on the policy to authenticate the users?

  • A. EAP-GTC
  • B. EAP-TLS
  • C. LEAP
  • D. MS-CHAPv2
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

An engineer must configure guest access on Cisco ISE for company visitors. Which step must be taken
on the Cisco ISE PSNs before a guest portal is configured?

  • A. Enable profiling services.
  • B. Install SSL certificates.
  • C. Create a node group.
  • D. Enable session services.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

Which action must be taken before configuring the Secure Client Agent profile when creating the
Secure Client configuration for ISE posture services?

  • A. Create a posture remediation condition policy for the Agent profile.
  • B. Configure the posture policy for Secure Client posturing module.
  • C. Create a posture condition that references the Secure Client package.
  • D. Upload the Secure Client packages and the Secure Client compliance modules.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

An engineer is configuring a new Cisco ISE node. The Cisco ISE must make authorization decisions
based on the threat and vulnerability attributes received from the threat and vulnerability adapters.
Which persona must be enabled?

  • A. Monitoring
  • B. Administration
  • C. pxGrid
  • D. Policy Service
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

An administrator must configure Cisco ISE to send CoA requests to a Cisco switch using SNMP. These
configurations were already performed:
enabled SNMP on the switch
added the switch to Cisco ISE
configured a network device profile
configured the NAD port detection method
configured the operation to be performed on the switch port
configured an authorization profile
Which two configurations must be performed to send the CoA requests? (Choose two.)

  • A. Select the CoA type as SNMP in the network device profile.
  • B. Configure the SNMP server in Cisco ISE.
  • C. Configure SNMP authentication in Cisco ISE.
  • D. Configure a network device group.
  • E. Configure the switch SNMP settings of the NAD.
Answer:

A, E

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 11

A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able
to submit CSR through the end devices. Which two features must be enabled to meet the
requirement?
(Choose two.)

  • A. Define a certificate group tag.
  • B. A new BYOD portal must be created.
  • C. A certificate provisioning portal must be configured.
  • D. Cisco ISE Internal CA service must be enabled.
  • E. Add SuperAdmin account into portal admin group.
Answer:

C, D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 12

Which CLI command must be configured on the switchport to immediately run the MAB process if a
non-802.1X capable endpoint connects to the port?

  • A. authentication order mab dot1x
  • B. authentication fallback
  • C. dot1x pae authenticator
  • D. access-session port-control auto
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

An administrator is editing a csv list of endpoints and wants to reprofile some of the devices
indefinitely before importing the list into Cisco ISE. Which field and Boolean value must be changed
for the devices before the list is reimported?

  • A. Identity Group Assignment field and Static Assignment field set to the value FALSE
  • B. Policy Assignment field and Static Assignment field set to the value TRUE
  • C. Policy Assignment field and Static Assignment field set to the value FALSE
  • D. Identity Group Assignment field and Static Assignment field set to the value TRUE
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

An engineer must use Cisco ISE profiler services to provide network access to Cisco IP phones that
cannot support 802.1X. Cisco ISE is configured to use the access switch device sensor information
system-description and platform-type to profile Cisco IP phones and allow access. Which two
protocols must be configured on the switch to complete the configuration? (Choose two.)

  • A. CDP
  • B. EAPOL
  • C. LLDP
  • D. SNMP
  • E. STP
Answer:

A, C

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 15

What is the default port used by Cisco ISE for NetFlow version 9 probe?

  • A. UDP 9996
  • B. UDP 9997
  • C. UDP 9998
  • D. UDP 9999
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2