BYOD
Drill 19 practice questions focused entirely on BYOD for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A network administrator is deploying BYOD onboarding with the ISE internal CA. Corporate policy requires that only endpoints already listed in a specific ISE endpoint identity group be permitted to complete certificate provisioning, while all other personal devices are silently denied enrollment. Which ISE configuration approach best enforces this allow-list requirement during the BYOD flow?
A network engineer is designing BYOD onboarding for a Cisco WLC deployment. The requirement is that employees first associate to an open (or PSK) provisioning SSID to register their device and download the native supplicant profile and certificate, then move to a secure 802.1X SSID for production access. Which BYOD deployment model does this describe, and what must the WLC configuration include to support the transition?
A network engineer is preparing ISE to issue certificates to BYOD endpoints using the ISE internal CA. During validation, the engineer notices that the certificates presented to onboarded endpoints must chain to a trusted root. To ensure the internal CA can sign endpoint certificates while maintaining a proper trust chain in a distributed deployment, which statement correctly describes how the ISE internal CA hierarchy is structured?
A network administrator is preparing Cisco ISE to issue certificates to employee-owned devices during BYOD onboarding using the ISE internal CA. When configuring the certificate template that will be bound to the BYOD portal's provisioning flow, which combination of settings must the administrator define within the certificate template itself?
A network administrator has deployed BYOD onboarding using the ISE internal CA to issue certificates to employee devices. After several months, a security team requirement mandates that ISE must validate the revocation status of endpoint certificates in real time during EAP-TLS authentication, rather than relying on periodically downloaded lists. Which mechanism should the administrator configure in the certificate authentication settings to meet this requirement with the ISE internal CA?
An engineer configures BYOD onboarding using the ISE internal CA. During EAP-TLS authentication after onboarding, employee endpoints that received a certificate from the ISE internal CA fail with a 'certificate chain could not be validated' error on the PSN. The endpoint certificate itself is valid and not expired. What must the engineer verify to resolve the trust validation failure?
A user calls the help desk reporting that a personal tablet they previously onboarded through BYOD has been lost. The security team wants the user to be able to immediately prevent that specific device from accessing the network without waiting for an administrator, while other registered devices belonging to that same user continue working normally. Which ISE capability should the user be directed to use?
A network engineer is defining the ISE internal CA certificate template used to issue certificates to endpoints during BYOD onboarding. The engineer wants the issued certificates to be usable for 802.1X EAP-TLS authentication where the endpoint acts as the client presenting its certificate to ISE. Which Extended Key Usage (EKU) value must be included in the certificate template so the issued endpoint certificates are valid for this purpose?
A network engineer is building a BYOD flow in Cisco ISE for a corporate wireless network. Employees using Windows laptops, macOS laptops, Android phones, and iOS devices must all be able to onboard through the same single-SSID flow. During testing, Android users report that after registering they are prompted to install an app, while Windows users receive a downloadable executable. The engineer wants to understand which ISE component determines the platform-specific onboarding logic (which files, wizards, and profiles are delivered per operating system). Which ISE configuration element is responsible for this behavior?
A network architect is documenting the BYOD onboarding options for a new wireless deployment before implementation. Management wants to minimize the number of SSIDs broadcast in the environment while still allowing employees to onboard personal devices and receive certificates from the ISE internal CA. Which BYOD onboarding approach should the architect recommend to satisfy this requirement?
A network engineer is finalizing BYOD onboarding for a corporate campus. Windows and macOS laptops must be provisioned with a certificate and a configured 802.1X supplicant for the secure SSID. During testing, users report that after clicking the onboarding link, they are prompted to download and run a temporary application that configures the device and then does not remain installed. The engineer wants to confirm what component performs this one-time provisioning on the endpoint. Which ISE component is responsible for this behavior?
A network engineer is enabling single-SSID equivalent BYOD onboarding on a Cisco Catalyst switch for wired employees who must be redirected to the ISE BYOD portal to run the Native Supplicant Provisioning wizard. After the initial 802.1X/EAP authentication succeeds, ISE returns an authorization result containing a redirect URL and the name of a redirect ACL, but clients open a browser and never see the ISE portal. Which switch-side configuration element is most likely missing and required for the redirection to function?
During BYOD single-SSID onboarding on a Cisco WLC, an employee named jsmith authenticates with PEAP-MSCHAPv2, is redirected to the BYOD portal, and the native supplicant provisioning installs a certificate issued by the ISE internal CA. The security team wants ISE authorization policies to later match this endpoint to the specific user who onboarded it. Which endpoint certificate attribute is populated by default during ISE internal CA enrollment to enable this correlation?
You are configuring a Cisco WLC (AireOS) to support single-SSID BYOD onboarding with ISE using the internal CA. Wireless users authenticate via 802.1X, then ISE returns a URL redirect authorization result to send new devices to the BYOD portal for native supplicant provisioning. During testing, ISE never sends the CoA and the client is never redirected to the portal even though the authorization policy matches. Which WLAN setting on the WLC must be enabled for the redirect and CoA to function?
A network engineer is configuring single-SSID BYOD onboarding on a Cisco WLC (AireOS) using ISE as the RADIUS server with the internal CA. During the provisioning phase, the WLC must redirect the corporate employee's device to the ISE BYOD portal so the Native Supplicant Provisioning wizard can be installed. Which WLC configuration element is REQUIRED on the WLC to enable ISE to enforce this redirection during authorization?
An engineer is configuring single-SSID BYOD onboarding on a Cisco WLC (AireOS) using ISE with its internal CA. After a user authenticates via dot1x on the corporate SSID with an unregistered device, ISE returns an authorization result that references a named ACL to steer the client to the BYOD provisioning portal. During testing, the client associates but never receives the ISE redirect to the Native Supplicant Provisioning portal, even though the WLC's RADIUS NAC/CoA settings are correct. Which action on the WLC most likely resolves the missing redirect?
A network engineer is designing a single-SSID BYOD onboarding solution using a Cisco WLC and ISE with the internal CA. Employees connect to a WPA2-Enterprise SSID with their AD credentials via PEAP, and after registering their personal device they must transition to EAP-TLS on the SAME SSID without manually reconnecting to a different network. Which mechanism must the WLC support and ISE trigger to move the endpoint from the provisioning state to the certificate-authenticated state after the device is onboarded?
An employee reports that their personal tablet, previously onboarded through the BYOD flow, has been lost. The security team wants to immediately prevent that specific device from gaining network access via its issued certificate, while allowing the employee to re-register a replacement device. Which ISE action accomplishes this?
A company wants employees to onboard their personal devices for secure network access. When users connect to the corporate SSID and authenticate, they should be redirected to a portal that guides them through installing a supplicant configuration and issuing a certificate to the device, after which they gain full access. Which ISE portal type must the administrator configure to accomplish this device onboarding workflow?
More 300-715 practice
Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.
← Back to 300-715 overview