Hard 300-715 practice questions
Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 22 hard questions available — no sign-up, always free.
A network engineer is preparing ISE to issue certificates to BYOD endpoints using the ISE internal CA. During validation, the engineer notices that the certificates presented to onboarded endpoints must chain to a trusted root. To ensure the internal CA can sign endpoint certificates while maintaining a proper trust chain in a distributed deployment, which statement correctly describes how the ISE internal CA hierarchy is structured?
An engineer configures BYOD onboarding using the ISE internal CA. During EAP-TLS authentication after onboarding, employee endpoints that received a certificate from the ISE internal CA fail with a 'certificate chain could not be validated' error on the PSN. The endpoint certificate itself is valid and not expired. What must the engineer verify to resolve the trust validation failure?
A network administrator joins Cisco ISE to an Active Directory domain that spans multiple sites, each with its own domain controllers. Users at a remote branch report intermittent authentication failures, and logs show ISE occasionally contacting a domain controller located across a slow WAN link in the corporate data center. Which ISE Active Directory configuration option should the administrator adjust to ensure ISE prefers domain controllers geographically closest to it?
A network engineer is deploying Central Web Authentication (CWA) for guest wireless users on a remote-site Cisco WLC where the APs operate in FlexConnect mode with local switching. Wired traffic from these APs does not traverse the WLC. Guests connect to an open SSID, associate via MAB, and are supposed to be redirected to the ISE guest portal. However, users associate but never receive the redirect. What must the engineer configure on the WLC to make the CWA redirection work in this FlexConnect local-switching scenario?
A security engineer wants Windows domain laptops to prove BOTH the machine's and the logged-in user's identity in a single EAP conversation, so that authorization can grant full access only when a corporate machine AND a valid domain user are authenticated together. Which authentication method should be configured in the ISE Allowed Protocols policy to achieve this?
A retail company uses ISE self-registered guest access. Marketing wants returning guests who registered last month to NOT have to re-register when they visit again this week, but the security team requires that stale guest endpoints be automatically removed after 30 days of inactivity to keep the endpoint database clean. As the ISE administrator, which configuration approach satisfies both requirements?
A network engineer deploys Central Web Authentication with a Cisco WLC. After a guest successfully authenticates on the ISE guest portal, the authorization result assigns the endpoint to a different VLAN than the one used during the redirect. Users report that after login, their browsers hang and their sessions eventually time out because the client keeps its original IP address, which is no longer valid on the new VLAN. Which guest portal setting should the engineer enable to resolve this issue?
A network engineer is deploying IBNS 2.0 on Cisco Catalyst switches integrated with ISE. During the pilot, management requires that all endpoints (including devices failing 802.1X) retain basic network connectivity for DHCP, DNS, and access to the remediation server, while authenticated devices receive full access. Unauthenticated traffic must still be filtered. Which host mode and deployment approach on the switchport best meets these requirements?
A network engineer is deploying IBNS 2.0 on a Cisco Catalyst switch running IOS-XE. The requirement is that during an authentication failure or RADIUS server unavailability, an endpoint should locally receive a predefined set of interface policies (VLAN and ACL) that are pushed and consistently applied without waiting for ISE. The engineer wants to define these policies once and reference them from multiple event-driven actions within a policy-map. Which IBNS 2.0 construct should the engineer configure to accomplish this?
A security engineer is integrating Cisco ISE with an OpenLDAP directory that stores user accounts and group memberships. The requirement is to authenticate users with PEAP-MSCHAPv2 and to authorize them based on their group membership. During testing, authentication consistently fails for all users, though the LDAP identity store test connection succeeds and group lookups return correct results. What is the most likely cause of the authentication failure?
A network engineer joins Cisco ISE to Active Directory and wants to ensure that only corporate laptops that have first authenticated the machine account to the domain can subsequently pass user 802.1X authentication. The company will NOT deploy EAP chaining or TEAP due to legacy supplicant limitations. Which ISE Active Directory feature should the engineer enable to enforce this requirement?
A network architect is designing a distributed Cisco ISE deployment for an enterprise that must support 50,000 concurrent endpoints with full redundancy. Company policy requires that RADIUS authentication requests never be handled by a node that also owns administration or monitoring functions. Which persona placement design satisfies these requirements?
A network engineer notices that ISE is generating a very high volume of profiler-related database updates, causing replication load between the PAN and PSNs. Investigation shows that endpoints are constantly sending updated DHCP and RADIUS attributes that only marginally change the endpoint records, with no impact on profile classification. Which profiler configuration option should the engineer enable to reduce this unnecessary replication and persistence overhead?
A network engineer is deploying ISE profiling for a large campus. Endpoints authenticate via MAB on switches, and the engineer wants ISE to collect DHCP attributes (such as dhcp-class-identifier) without deploying an ISE anycast helper or configuring 'ip helper-address' pointing to the PSN. The switches already forward RADIUS accounting to ISE. Which probe should the engineer enable to gather these DHCP attributes with minimal additional network configuration?
A network engineer deploys two Cisco ISE nodes in a small deployment. Both nodes have the PAN and MnT personas enabled, and both also run the PSN persona to authenticate endpoints. Management wants to know the maximum number of concurrent active endpoints this specific configuration can support, and whether it can be increased later without redesigning the deployment. Which statement correctly describes this deployment type and its scaling behavior?
A network engineer is deploying Cisco TrustSec across a campus. Several older access switches support 802.1X and downloadable ACLs but do NOT support inline SGT tagging or SXP. The engineer still wants endpoints connecting to these switches to receive a Security Group Tag so egress enforcement can occur on a capable distribution switch. Which approach allows ISE to assign an SGT to these endpoints despite the access-switch limitation?
A network engineer is deploying Cisco TrustSec and wants a Catalyst switch to authenticate to ISE and download its environment data (SGT-to-name mappings and the CTS environment) so it can participate in the TrustSec domain. The switch is configured with 'cts credentials id SW1 password <secret>' and points to ISE as its AAA server. What must be configured on ISE, and what does the switch obtain first, to enable this exchange?
A network engineer deploys 802.1X on access switches integrated with Cisco ISE. During a WAN outage, the switches lose connectivity to all ISE PSNs. The business requires that already-authenticated endpoints keep working and that newly connecting devices in the manufacturing area still receive limited network access even when ISE is unreachable. Which switch feature should the engineer configure to meet the requirement for new devices?
A security engineer is deploying posture assessment with Cisco Secure Client but the network access devices (a mix of third-party switches) do not support URL redirection. The engineer needs endpoints to still discover the Policy Service Node and complete client provisioning and posture. Which configuration approach allows the posture flow to succeed in this redirectless environment?
A network administrator configures ISE as a TACACS+ server for device administration on a set of IOS switches. Command authorization is enabled with 'aaa authorization commands 15 default group ISE-TACACS'. During a maintenance window, all ISE PSNs become unreachable. When the administrator logs in via the console (already authenticated locally), every privilege-level 15 command is rejected. What single configuration change on the switch will allow authorized local commands to execute when the TACACS+ servers are unreachable?
A network administrator is configuring TACACS+ device administration on Cisco ISE. Junior operators must be able to log into IOS switches, land directly in privileged EXEC (level 15), but only be permitted to run 'show' commands and 'ping' — all other commands must be denied. Which combination of TACACS+ policy result components should be assigned to the operator authorization rule?
An engineer is configuring TACACS+ device administration in ISE for a group of switches. The authorization policy rule for the 'JuniorNetOps' group references two command sets: 'CS-ShowOnly' (permits 'show' commands, denies all others) and 'CS-IntConfig' (permits 'configure terminal' and 'interface' commands). Both command sets are added to the same authorization result. When a junior engineer runs 'interface GigabitEthernet1/0/1', the command is permitted. When they run 'reload', it is denied. How does ISE evaluate multiple command sets attached to a single authorization result?