300-715 cheat sheet

A one-page reference for the Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
Cisco
Level
Professional
Questions
90
Time
90 min
Mock pass mark
75%
Domains
7
Practice Qs
139
Code
300-715

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

ISE
Cisco Identity Services Engine (ISE) is the policy platform that provides authentication, authorization, and accounting plus profiling, posture, and guest services for network access control. SISE is entirely about deploying and configuring ISE.
802.1X
This is the IEEE 802.1X standard for port-based network access control, where a supplicant authenticates to an authenticator (switch/WLC) against ISE as the RADIUS server. SISE covers 802.1X as the primary wired/wireless authentication method.
MAB
MAC Authentication Bypass (MAB) authenticates endpoints that cannot do 802.1X by using their MAC address as the identity. SISE covers MAB as a fallback and for headless devices in policy enforcement.
RADIUS
RADIUS is the AAA protocol ISE uses to authenticate and authorize network access requests from switches, WLCs, and VPN devices. SISE covers RADIUS (and CoA) as the core enforcement channel.
CoA
Change of Authorization (CoA) lets ISE dynamically change or terminate an active session — for reauthentication, posture remediation, or quarantine — without the endpoint reconnecting. SISE covers CoA across profiler, posture, and BYOD flows.
TrustSec
Cisco TrustSec enforces software-defined segmentation using Security Group Tags (SGTs) assigned by ISE instead of IP-based ACLs. SISE covers configuring TrustSec and SGTs under policy enforcement.
SGT
A Security Group Tag (SGT) is a label ISE assigns to a session that downstream devices use to enforce TrustSec segmentation policy. SISE covers SGT assignment and SGACL enforcement.
Profiler
The ISE Profiler classifies connected endpoints by type (phone, printer, camera, etc.) using probes such as DHCP, RADIUS, SNMP, and DNS. SISE's Profiler domain covers configuring probes and profiling policies.
Posture
Posture assessment checks that an endpoint meets compliance requirements (patches, antivirus, configuration) before granting full access, using the AnyConnect/Secure Client posture module. SISE covers posture under Endpoint Compliance.
Secure Client
Cisco Secure Client (formerly AnyConnect) provides the supplicant and posture agent that interact with ISE for authentication and compliance. SISE covers its role in posture and BYOD.
BYOD
Bring Your Own Device (BYOD) is the ISE workflow that onboards personal devices with certificate provisioning and My Devices self-service. SISE's BYOD domain covers native supplicant provisioning and the BYOD portals.
Guest Services
Guest Services in ISE provide web authentication and sponsored or self-registered guest access through customizable portals. SISE's Web Auth and Guest Services domain covers hotspot, self-registered, and sponsored guest flows.
Web Authentication
Web Authentication redirects unauthenticated users to an ISE portal to sign in via a browser, used for guests and as a fallback. SISE covers central and local web auth in the Web Auth and Guest Services domain.
TACACS+
TACACS+ is the AAA protocol ISE uses for device administration, providing granular command authorization and accounting for network device logins. SISE covers TACACS+ under Network Access Device Administration.
pxGrid
Cisco Platform Exchange Grid (pxGrid) is the framework ISE uses to share contextual identity and session information with other security products. SISE covers pxGrid for integration and ecosystem enforcement.