Architecture and Deployment
Drill 11 practice questions focused entirely on Architecture and Deployment for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A company currently runs a single standalone ISE node handling all personas for 4,500 endpoints. They plan to add a disaster-recovery site and grow to 12,000 concurrent endpoints within a year, and they want administrative and monitoring redundancy across two data centers. Which ISE deployment model should the network architect recommend to meet these requirements?
A network administrator is distributing personas across a distributed Cisco ISE deployment. The security team complains that live authentication logs, detailed session reports, and troubleshooting data are difficult to retrieve during peak load, and they want a dedicated node to handle this function so the policy service nodes are not burdened with reporting queries. Which persona should the administrator dedicate to a node to address this requirement?
A network architect is designing a distributed Cisco ISE deployment for an enterprise that must support 50,000 concurrent endpoints with full redundancy. Company policy requires that RADIUS authentication requests never be handled by a node that also owns administration or monitoring functions. Which persona placement design satisfies these requirements?
An engineer is building a new distributed Cisco ISE deployment with four nodes. Management insists that all configuration changes, policy edits, and node registrations be performed from a single authoritative source, while a second node stands ready to take over administration if the first fails. Which persona configuration on the first node satisfies this requirement?
A network engineer manages a distributed Cisco ISE deployment with two nodes running the Administration persona: a Primary PAN and a Secondary PAN. During a hardware failure, the Primary PAN becomes permanently unavailable. The engineer needs to restore full administrative and configuration capability to the deployment. What must the engineer do?
A network engineer is deploying multiple Policy Service Nodes (PSNs) behind a load balancer at a data center. Management wants the PSNs to detect a peer failure quickly and reset any orphaned RADIUS/TACACS+ sessions so endpoints can re-authenticate against a surviving node. Which PSN configuration should the engineer implement to meet this requirement?
A network architect is designing a distributed Cisco ISE 3.x deployment for a large enterprise that will integrate with Cisco Secure Firewall, Secure Network Analytics, and a third-party SIEM for contextual data sharing via pxGrid. The design must support the maximum number of session endpoints while ensuring pxGrid publishing and subscription services remain highly available under peak load. Which persona placement approach should the architect adopt?
A security engineer is deploying Cisco ISE to share contextual identity information with a Cisco Secure Firewall Management Center and a Secure Network Analytics collector. The team needs ISE to act as a publish/subscribe controller so external ecosystem partners can consume session and threat context. Which ISE persona must be enabled to fulfill this requirement?
A network engineer deploys two Cisco ISE nodes in a small deployment. Both nodes have the PAN and MnT personas enabled, and both also run the PSN persona to authenticate endpoints. Management wants to know the maximum number of concurrent active endpoints this specific configuration can support, and whether it can be increased later without redesigning the deployment. Which statement correctly describes this deployment type and its scaling behavior?
A network engineer is deploying a Cisco ISE 3.x virtual appliance to serve as a dedicated Policy Service Node (PSN) supporting up to 20,000 concurrent sessions. The virtualization team allocated the VM with sufficient vCPU and RAM but reports intermittent authentication latency and warnings in ISE about performance degradation. Which action should the engineer recommend to ensure the virtual PSN meets Cisco's supported performance specifications?
A network administrator is deploying twelve new Cisco ISE 3.x virtual appliances across remote data centers. To avoid manually running the setup wizard on each node, they want to use ISE Zero-Touch Provisioning (ZTP) so the nodes automatically receive their initial network and node configuration on first boot. Which mechanism does ISE ZTP rely on to deliver the initial configuration securely to a freshly booted node?
More 300-715 practice
Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.
← Back to 300-715 overview