Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) · Domain 6 · 10% of exam

Endpoint Compliance

Drill 14 practice questions focused entirely on Endpoint Compliance for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer14 questions
Question 1 of 14

A network engineer is deploying posture services in ISE for corporate Windows endpoints connecting via wired 802.1X. When a compliant endpoint first authenticates but has never run posture assessment, the engineer wants ISE to redirect the user to install the agent and remain restricted until assessment completes. Which posture session status should the authorization policy match to trigger the redirect to the Client Provisioning portal?

Reviewed for accuracy · Report an issue
Question 2 of 14

A security engineer must deploy posture assessment for a group of contractor laptops. These laptops are managed by a third party, so the engineer is not permitted to permanently install any software on them, but posture must still be evaluated each time the contractors connect. Which posture agent option in ISE meets this requirement?

Reviewed for accuracy · Report an issue
Question 3 of 14

A network administrator has enabled posture services in ISE. Windows corporate laptops connecting via wired 802.1X are being redirected to the Client Provisioning Portal, but instead of receiving the Cisco Secure Client agent, users see a message that no client provisioning policy matched. AnyConnect/Secure Client configurations and agent resources have already been uploaded. What is the MOST likely reason the client provisioning policy is not matching?

Reviewed for accuracy · Report an issue
Question 4 of 14

A network administrator is deploying posture services on ISE. Windows corporate endpoints connect via 802.1X and must have the AnyConnect ISE Posture module installed before being assessed. When a non-compliant endpoint without the agent connects, the authorization policy redirects it to a portal so the required software can be delivered. Which ISE component must be configured to define which agent and compliance module version is pushed to the endpoint based on its operating system?

Reviewed for accuracy · Report an issue
Question 5 of 14

A network administrator is deploying posture services with the Cisco Secure Client (AnyConnect) posture module on corporate Windows endpoints. During client provisioning, users report that although the Secure Client posture module installs successfully, endpoints repeatedly show 'posture unknown' and cannot evaluate anti-malware conditions. The administrator confirms the posture agent is running. Which component must be present and correctly configured in ISE for the posture module to obtain the definitions needed to assess anti-malware, disk encryption, and patch conditions?

Reviewed for accuracy · Report an issue
Question 6 of 14

A security engineer must ensure that Windows endpoints connecting through 802.1X are considered compliant only if their installed anti-malware product has virus definitions no older than 3 days. The engineer wants to use a built-in, vendor-aware check that automatically recognizes supported anti-malware vendors and their definition status rather than manually specifying registry keys or file paths. Which posture condition type should the engineer configure in ISE?

Reviewed for accuracy · Report an issue
Question 7 of 14

A security engineer must enforce that all corporate Windows endpoints have both a specific antivirus definition file present AND a particular registry key set to a required value before granting full network access. Neither condition alone is sufficient — both must be true simultaneously. Which ISE posture configuration approach correctly implements this requirement?

Reviewed for accuracy · Report an issue
Question 8 of 14

A security engineer must ensure that all corporate Windows endpoints have their patch management software installed and reporting that no critical patches are missing before granting full network access. The engineer wants ISE to natively validate this state rather than checking for a specific file or registry key. Which posture condition type should be used?

Reviewed for accuracy · Report an issue
Question 9 of 14

A security engineer must ensure that corporate Windows endpoints are running a specific host-based DLP service before granting full network access through ISE posture. If the service is stopped, the endpoint should be marked noncompliant and prompted to remediate. Which posture condition type should the engineer configure to evaluate whether the DLP service is currently running on the endpoint?

Reviewed for accuracy · Report an issue
Question 10 of 14

A security engineer must ensure that Windows endpoints do not have any USB mass storage devices connected before granting full network access via posture. The requirement should evaluate the presence of removable storage as part of the posture check. Which posture condition type should the engineer configure to meet this requirement?

Reviewed for accuracy · Report an issue
Question 11 of 14

A security engineer configures posture for corporate laptops running Cisco Secure Client. Management requires that once an endpoint is found compliant, its posture status remains valid for 4 hours before the agent must silently re-verify compliance again, without forcing the user through a new full login. Which ISE posture setting achieves this behavior?

Reviewed for accuracy · Report an issue
Question 12 of 14

An ISE administrator is building a posture requirement policy for corporate Windows endpoints. The requirement checks that a specific patch-management service is running. The security team wants noncompliant endpoints to still be granted network access, but they want the user to receive a message informing them of the failed check with an option to remediate later. Which requirement enforcement type should the administrator assign to this posture requirement?

Reviewed for accuracy · Report an issue
Question 13 of 14

A security engineer is deploying posture assessment with Cisco Secure Client but the network access devices (a mix of third-party switches) do not support URL redirection. The engineer needs endpoints to still discover the Policy Service Node and complete client provisioning and posture. Which configuration approach allows the posture flow to succeed in this redirectless environment?

Reviewed for accuracy · Report an issue
Question 14 of 14

A security engineer must deploy posture assessment on corporate laptops that have no interactive logged-in user (kiosk-style machines running continuously). The requirement is that endpoint compliance be evaluated and remediated automatically without displaying any agent UI, notifications, or user prompts. Which AnyConnect ISE Posture agent operational mode meets this requirement?

Reviewed for accuracy · Report an issue

More 300-715 practice

Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.

← Back to 300-715 overview