Policy Enforcement
Drill 20 practice questions focused entirely on Policy Enforcement for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A network engineer is deploying 802.1X on wired access switches for the first time in a large enterprise. Management requires that no legitimate users lose network connectivity during the rollout, even if their supplicant is misconfigured or ISE authorization policies are incomplete. The engineer needs to observe authentication results in ISE and correct policy issues before enforcing access control. Which switchport configuration approach best meets this requirement?
A network administrator joins Cisco ISE to an Active Directory domain that spans multiple sites, each with its own domain controllers. Users at a remote branch report intermittent authentication failures, and logs show ISE occasionally contacting a domain controller located across a slow WAN link in the corporate data center. Which ISE Active Directory configuration option should the administrator adjust to ensure ISE prefers domain controllers geographically closest to it?
An ISE administrator has successfully joined ISE to an Active Directory domain and can authenticate domain users. However, when building an authorization policy, the administrator cannot select any AD security groups from the external group dropdown, and the condition list is empty. Authentication against AD works correctly. What must the administrator do to make AD groups available for use in authorization conditions?
A security engineer integrates Cisco ISE with two separate Active Directory forests that have no trust relationship between them: 'corp.example.com' for employees and 'contractor.example.net' for contract staff. Both forests must be usable as identity sources for 802.1X authentication. The engineer wants ISE to try each directory in a defined order and stop at the first that can authenticate the user. Which ISE configuration meets this requirement?
An administrator is deploying EAP-TLS for corporate laptops. Users present certificates where the Subject Alternative Name (SAN) contains the user's UPN, but the Subject Common Name (CN) field is blank. Authentication is failing during the identity lookup against Active Directory. What must the administrator configure so ISE extracts the correct principal name from the certificate for the AD lookup?
A network administrator configures an ISE authentication policy for a dot1x-based wired deployment. Contractors authenticate using EAP-TLS certificates stored in an LDAP directory, while full-time employees authenticate using PEAP-MSCHAPv2 credentials in Active Directory. Both user types hit the same authentication policy rule. The administrator wants ISE to first attempt to validate the user against Active Directory, and if the user is not found there, fall through and check the LDAP store before rejecting the request. Which configuration achieves this behavior?
A network engineer is building an authorization profile in ISE for corporate wireless users who should be placed into a dynamic VLAN. The switching and wireless team have standardized on referencing VLANs by name (CORP_DATA) rather than by ID number across all access devices. Which combination of RADIUS attributes must the authorization profile return so that the NAD assigns the client to the correct VLAN by name?
A network engineer is deploying 802.1X on access switches that connect both IP phones and PCs on the same port using multi-domain authentication (MDA). The Cisco IP phones authenticate successfully via MAB against ISE, but they fail to gain access to the voice VLAN even though the correct VLAN is being assigned. In the ISE authorization profile applied to the phones, which setting must be enabled so the switch permits the endpoint into the voice domain?
An ISE administrator has built an authorization policy set for wired 802.1X. The policy set contains these rules in order: (1) 'Employee_Full' matches AD group 'Domain Users' and permits full access, (2) 'Contractor_Limited' matches AD group 'Contractors' and applies a restricted dACL. A user who is a member of both 'Domain Users' and 'Contractors' in Active Directory authenticates successfully. The administrator expects this user to receive the restricted contractor access but instead sees full access being granted. What is the cause of this behavior, and how should it be corrected?
A network administrator is building an authorization profile in Cisco ISE for corporate laptops that authenticate via 802.1X. Security policy requires that each authenticated session be re-validated every 2 hours without disconnecting the endpoint if it is still active, and the timer value must be pushed to the switch as part of the RADIUS Access-Accept. Which configuration in the authorization profile accomplishes this requirement?
A network engineer configures a downloadable ACL (dACL) in ISE to be pushed to Cisco Catalyst switches as part of an authorization profile for contractor endpoints. After saving the authorization profile, the engineer wants to ensure the switches will accept and apply the dACL without syntax errors. Which action should the engineer take within ISE before deploying the dACL to production?
A network administrator is configuring an authorization policy on Cisco ISE for corporate laptops that pass 802.1X EAP-TLS authentication on wired access switches. The requirement is that authenticated laptops must be placed in the corporate data VLAN and simultaneously receive a downloadable ACL (dACL) that permits only business application traffic. Which combination must be configured in the authorization profile to meet both requirements?
An engineer is deploying wired 802.1X on Cisco Catalyst access switches. Each access port connects a Cisco IP phone with a PC daisy-chained behind it. The security policy requires that the phone authenticate in the voice domain and the PC authenticate independently in the data domain, but no more than one endpoint should ever be authorized in the data domain on a single port. Which switchport host mode meets these requirements?
A security engineer wants Windows domain laptops to prove BOTH the machine's and the logged-in user's identity in a single EAP conversation, so that authorization can grant full access only when a corporate machine AND a valid domain user are authenticated together. Which authentication method should be configured in the ISE Allowed Protocols policy to achieve this?
A network engineer is deploying IBNS 2.0 on Cisco Catalyst switches integrated with ISE. During the pilot, management requires that all endpoints (including devices failing 802.1X) retain basic network connectivity for DHCP, DNS, and access to the remediation server, while authenticated devices receive full access. Unauthenticated traffic must still be filtered. Which host mode and deployment approach on the switchport best meets these requirements?
A network engineer is deploying IBNS 2.0 on a Cisco Catalyst switch running IOS-XE. The requirement is that during an authentication failure or RADIUS server unavailability, an endpoint should locally receive a predefined set of interface policies (VLAN and ACL) that are pushed and consistently applied without waiting for ISE. The engineer wants to define these policies once and reference them from multiple event-driven actions within a policy-map. Which IBNS 2.0 construct should the engineer configure to accomplish this?
A network engineer is integrating Cisco ISE with a third-party LDAP directory (OpenLDAP) to authenticate contractor accounts. During testing, users can be found and authenticated, but ISE cannot retrieve any group membership for authorization policy conditions. The engineer confirms the bind credentials are valid and the connection test succeeds. Which LDAP configuration element must be verified to resolve the missing group data?
An engineer is configuring an LDAP identity store on Cisco ISE to authenticate users against a third-party directory. Security policy requires that all directory traffic be encrypted and that ISE validate the LDAP server's identity before binding. In the LDAP identity source configuration, which combination of settings meets these requirements?
A security engineer is integrating Cisco ISE with an OpenLDAP directory that stores user accounts and group memberships. The requirement is to authenticate users with PEAP-MSCHAPv2 and to authorize them based on their group membership. During testing, authentication consistently fails for all users, though the LDAP identity store test connection succeeds and group lookups return correct results. What is the most likely cause of the authentication failure?
A network engineer is deploying MAB for a group of legacy badge printers on switch ports that are also configured for 802.1X. The printers do not support any 802.1X supplicant. On the switchport, the engineer wants the switch to attempt 802.1X first and only fall back to MAB if the endpoint does not respond to EAP requests. Which switchport configuration achieves this behavior?
More 300-715 practice
Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.
← Back to 300-715 overview