January 8, 2019

What to do with 300 208 sisas

Q1. Which three components comprise the Cisco ISE profiler? (Choose three.)

A. the sensor, which contains one or more probes

B. the probe manager

C. a monitoring tool that connects to the Cisco ISE

D. the trigger, which activates ACLs

E. an analyzer, which uses configured policies to evaluate endpoints

F. a remitter tool, which fails over to redundant profilers

Answer: A,B,E

Q2. Cisco ISE distributed deployments support which three features? (Choose three.)

A. global implementation of the profiler service CoA

B. global implementation of the profiler service in Cisco ISE

C. configuration to send system logs to the appropriate profiler node

D. node-specific probe configuration

E. server-specific probe configuration

F. NetFlow probes

Answer: A,C,D

Q3. What attribute could be obtained from the SNMP query probe?



C. DHCP class identifier

D. User agent

Answer: B

Q4. Which feature of Cisco ASA allows VPN users to be postured against Cisco ISE without requiring an inline posture node?

A. RADIUS Change of Authorization

B. device tracking

C. DHCP snooping

D. VLAN hopping

Answer: A

Q5. What are the initial steps to configure an ACS as a TACACS server?

A. 1. Choose Network Devices and AAA Clients > Network Resources.2. Click Create.

B. 1. Choose Network Resources > Network Devices and AAA Clients.2. Click Create.

C. 1. Choose Network Resources > Network Devices and AAA Clients.2. Click Manage.

D. 1. Choose Network Devices and AAA Clients > Network Resources.2. Click Install.

Answer: B

Q6. A network administration wants to set up a posture condition on Cisco ISE to check for the file name Posture.txt in C:\\ on a Windows machine. Which condition must the network administrator configuration?

A. Service condition

B. Registry condition

C. Application condition

D. File condition

Answer: D

Q7. In Cisco ISE 1.3 and above, which two operations are allowed on Endpoint Certificates pages for issued endpoint certificates on the admin portal? (Choose two.)

A. unrevoke

B. delete

C. view

D. export

E. revoke

Answer: C,E

Q8. Which command would be used in order to maintain a single open connection between a network access device and a tacacs server?

A. tacacs-server host timeout

B. tacacs-server host single-connection

C. tacacs-server host <ip address>

D. tacacs-server host <ip address> single-connection

Answer: D

Q9. Which three statements about the Cisco wireless IPS solution are true? (Choose three.)

A. It enables stations to remain in power-save mode, except at specified intervals to receive data from the access point.

B. It detects spoofed MAC addresses.

C. It identifies potential RF jamming attacks.

D. It protects against frame and device spoofing.

E. It allows the WLC to failover because of congestion.

Answer: B,C,D

Q10. Which command is useful when troubleshooting AAA Authentication between a Cisco router and the AAA server?

A. test aaa-server test cisco cisco123 all new-code

B. test aaa group7 tacacs+ auth cisco123 new-code

C. test aaa group tacacs+ cisco cisco123 new-code

D. test aaa-server tacacs+ group7 cisco cisco123 new-code

Answer: C

