Medium 300-715 practice questions
Applied — put a concept to work in a realistic situation. 117 medium questions available — no sign-up, always free.
A network administrator is deploying BYOD onboarding with the ISE internal CA. Corporate policy requires that only endpoints already listed in a specific ISE endpoint identity group be permitted to complete certificate provisioning, while all other personal devices are silently denied enrollment. Which ISE configuration approach best enforces this allow-list requirement during the BYOD flow?
A network engineer is designing BYOD onboarding for a Cisco WLC deployment. The requirement is that employees first associate to an open (or PSK) provisioning SSID to register their device and download the native supplicant profile and certificate, then move to a secure 802.1X SSID for production access. Which BYOD deployment model does this describe, and what must the WLC configuration include to support the transition?
A network administrator is preparing Cisco ISE to issue certificates to employee-owned devices during BYOD onboarding using the ISE internal CA. When configuring the certificate template that will be bound to the BYOD portal's provisioning flow, which combination of settings must the administrator define within the certificate template itself?
A network administrator has deployed BYOD onboarding using the ISE internal CA to issue certificates to employee devices. After several months, a security team requirement mandates that ISE must validate the revocation status of endpoint certificates in real time during EAP-TLS authentication, rather than relying on periodically downloaded lists. Which mechanism should the administrator configure in the certificate authentication settings to meet this requirement with the ISE internal CA?
A user calls the help desk reporting that a personal tablet they previously onboarded through BYOD has been lost. The security team wants the user to be able to immediately prevent that specific device from accessing the network without waiting for an administrator, while other registered devices belonging to that same user continue working normally. Which ISE capability should the user be directed to use?
A network engineer is defining the ISE internal CA certificate template used to issue certificates to endpoints during BYOD onboarding. The engineer wants the issued certificates to be usable for 802.1X EAP-TLS authentication where the endpoint acts as the client presenting its certificate to ISE. Which Extended Key Usage (EKU) value must be included in the certificate template so the issued endpoint certificates are valid for this purpose?
A network engineer is building a BYOD flow in Cisco ISE for a corporate wireless network. Employees using Windows laptops, macOS laptops, Android phones, and iOS devices must all be able to onboard through the same single-SSID flow. During testing, Android users report that after registering they are prompted to install an app, while Windows users receive a downloadable executable. The engineer wants to understand which ISE component determines the platform-specific onboarding logic (which files, wizards, and profiles are delivered per operating system). Which ISE configuration element is responsible for this behavior?
A network architect is documenting the BYOD onboarding options for a new wireless deployment before implementation. Management wants to minimize the number of SSIDs broadcast in the environment while still allowing employees to onboard personal devices and receive certificates from the ISE internal CA. Which BYOD onboarding approach should the architect recommend to satisfy this requirement?
A network engineer is finalizing BYOD onboarding for a corporate campus. Windows and macOS laptops must be provisioned with a certificate and a configured 802.1X supplicant for the secure SSID. During testing, users report that after clicking the onboarding link, they are prompted to download and run a temporary application that configures the device and then does not remain installed. The engineer wants to confirm what component performs this one-time provisioning on the endpoint. Which ISE component is responsible for this behavior?
A network engineer is enabling single-SSID equivalent BYOD onboarding on a Cisco Catalyst switch for wired employees who must be redirected to the ISE BYOD portal to run the Native Supplicant Provisioning wizard. After the initial 802.1X/EAP authentication succeeds, ISE returns an authorization result containing a redirect URL and the name of a redirect ACL, but clients open a browser and never see the ISE portal. Which switch-side configuration element is most likely missing and required for the redirection to function?
During BYOD single-SSID onboarding on a Cisco WLC, an employee named jsmith authenticates with PEAP-MSCHAPv2, is redirected to the BYOD portal, and the native supplicant provisioning installs a certificate issued by the ISE internal CA. The security team wants ISE authorization policies to later match this endpoint to the specific user who onboarded it. Which endpoint certificate attribute is populated by default during ISE internal CA enrollment to enable this correlation?
You are configuring a Cisco WLC (AireOS) to support single-SSID BYOD onboarding with ISE using the internal CA. Wireless users authenticate via 802.1X, then ISE returns a URL redirect authorization result to send new devices to the BYOD portal for native supplicant provisioning. During testing, ISE never sends the CoA and the client is never redirected to the portal even though the authorization policy matches. Which WLAN setting on the WLC must be enabled for the redirect and CoA to function?
A network engineer is configuring single-SSID BYOD onboarding on a Cisco WLC (AireOS) using ISE as the RADIUS server with the internal CA. During the provisioning phase, the WLC must redirect the corporate employee's device to the ISE BYOD portal so the Native Supplicant Provisioning wizard can be installed. Which WLC configuration element is REQUIRED on the WLC to enable ISE to enforce this redirection during authorization?
An engineer is configuring single-SSID BYOD onboarding on a Cisco WLC (AireOS) using ISE with its internal CA. After a user authenticates via dot1x on the corporate SSID with an unregistered device, ISE returns an authorization result that references a named ACL to steer the client to the BYOD provisioning portal. During testing, the client associates but never receives the ISE redirect to the Native Supplicant Provisioning portal, even though the WLC's RADIUS NAC/CoA settings are correct. Which action on the WLC most likely resolves the missing redirect?
A network engineer is designing a single-SSID BYOD onboarding solution using a Cisco WLC and ISE with the internal CA. Employees connect to a WPA2-Enterprise SSID with their AD credentials via PEAP, and after registering their personal device they must transition to EAP-TLS on the SAME SSID without manually reconnecting to a different network. Which mechanism must the WLC support and ISE trigger to move the endpoint from the provisioning state to the certificate-authenticated state after the device is onboarded?
A network engineer is deploying Central Web Authentication (CWA) on a Catalyst switch running IOS. Endpoints authenticate via MAB, and ISE returns an authorization result containing a redirect URL and a redirect ACL. However, after connecting, test endpoints receive an IP address but the browser never displays the ISE guest portal — the redirection simply times out. RADIUS accounting and the CoA are confirmed working. Which switch configuration step is most likely missing and required for the redirect to function?
A network engineer is deploying 802.1X on wired access switches for the first time in a large enterprise. Management requires that no legitimate users lose network connectivity during the rollout, even if their supplicant is misconfigured or ISE authorization policies are incomplete. The engineer needs to observe authentication results in ISE and correct policy issues before enforcing access control. Which switchport configuration approach best meets this requirement?
An ISE administrator has successfully joined ISE to an Active Directory domain and can authenticate domain users. However, when building an authorization policy, the administrator cannot select any AD security groups from the external group dropdown, and the condition list is empty. Authentication against AD works correctly. What must the administrator do to make AD groups available for use in authorization conditions?
A security engineer integrates Cisco ISE with two separate Active Directory forests that have no trust relationship between them: 'corp.example.com' for employees and 'contractor.example.net' for contract staff. Both forests must be usable as identity sources for 802.1X authentication. The engineer wants ISE to try each directory in a defined order and stop at the first that can authenticate the user. Which ISE configuration meets this requirement?
An administrator is deploying EAP-TLS for corporate laptops. Users present certificates where the Subject Alternative Name (SAN) contains the user's UPN, but the Subject Common Name (CN) field is blank. Authentication is failing during the identity lookup against Active Directory. What must the administrator configure so ISE extracts the correct principal name from the certificate for the AD lookup?
A network administrator configures an ISE authentication policy for a dot1x-based wired deployment. Contractors authenticate using EAP-TLS certificates stored in an LDAP directory, while full-time employees authenticate using PEAP-MSCHAPv2 credentials in Active Directory. Both user types hit the same authentication policy rule. The administrator wants ISE to first attempt to validate the user against Active Directory, and if the user is not found there, fall through and check the LDAP store before rejecting the request. Which configuration achieves this behavior?
A network engineer is building an authorization profile in ISE for corporate wireless users who should be placed into a dynamic VLAN. The switching and wireless team have standardized on referencing VLANs by name (CORP_DATA) rather than by ID number across all access devices. Which combination of RADIUS attributes must the authorization profile return so that the NAD assigns the client to the correct VLAN by name?
A network engineer is deploying 802.1X on access switches that connect both IP phones and PCs on the same port using multi-domain authentication (MDA). The Cisco IP phones authenticate successfully via MAB against ISE, but they fail to gain access to the voice VLAN even though the correct VLAN is being assigned. In the ISE authorization profile applied to the phones, which setting must be enabled so the switch permits the endpoint into the voice domain?
An ISE administrator has built an authorization policy set for wired 802.1X. The policy set contains these rules in order: (1) 'Employee_Full' matches AD group 'Domain Users' and permits full access, (2) 'Contractor_Limited' matches AD group 'Contractors' and applies a restricted dACL. A user who is a member of both 'Domain Users' and 'Contractors' in Active Directory authenticates successfully. The administrator expects this user to receive the restricted contractor access but instead sees full access being granted. What is the cause of this behavior, and how should it be corrected?
A network administrator is building an authorization profile in Cisco ISE for corporate laptops that authenticate via 802.1X. Security policy requires that each authenticated session be re-validated every 2 hours without disconnecting the endpoint if it is still active, and the timer value must be pushed to the switch as part of the RADIUS Access-Accept. Which configuration in the authorization profile accomplishes this requirement?