Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) · Domain 4 · 15% of exam

Profiler

Drill 20 practice questions focused entirely on Profiler for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A network engineer enables the ISE profiler service and wants ISE to automatically re-apply authorization whenever an endpoint's profile changes from a generic group to a more specific device type (for example, from 'Workstation' to 'Apple-Device'). The engineer navigates to the profiler configuration settings. Which global setting must be configured so that a profile change triggers a Change of Authorization for the affected endpoint?

Reviewed for accuracy · Report an issue
Question 2 of 20

An administrator has configured the ISE Profiler with the global CoA type set to 'No CoA'. During testing, an endpoint that initially matched a generic profile is later re-profiled as a corporate workstation after additional DHCP attributes are collected. The authorization policy grants different access based on the new profile. However, the endpoint retains its original, less-privileged access even after re-profiling completes. What is the reason for this behavior?

Reviewed for accuracy · Report an issue
Question 3 of 20

An administrator has enabled profiling CoA in ISE global settings. A workstation is initially profiled generically and receives limited access. Moments later, the DHCP probe collects additional attributes and ISE reclassifies the endpoint into a matching authorization policy that assigns a new VLAN. The switchport is configured for multiple endpoints (multi-auth) with a phone and PC on the same port. Which global profiler CoA type should the administrator configure so that only the reprofiled endpoint is reauthorized without disrupting the other device on the port?

Reviewed for accuracy · Report an issue
Question 4 of 20

A network administrator is building a custom profiler policy in ISE to identify a fleet of newly deployed medical infusion pumps. The devices consistently report a specific DHCP class-identifier value AND their MAC OUI belongs to a known vendor. The administrator wants the endpoint to match this custom profile only when BOTH attributes are present, and wants the endpoint to be assigned to the matching group only once the total certainty factor reaches the configured Minimum Certainty Factor. How should the administrator configure the profiler policy rules to meet this requirement?

Reviewed for accuracy · Report an issue
Question 5 of 20

A network administrator wants ISE to receive CDP, LLDP, and DHCP profiling data collected directly by the access switches, without configuring SPAN or a dedicated DHCP relay to ISE. The switches are Catalyst models that support Device Sensor. Which combination on the switch ensures ISE receives this data through the RADIUS probe?

Reviewed for accuracy · Report an issue
Question 6 of 20

An engineer wants ISE to profile endpoints using the DHCP host-name and requested parameter list attributes. The network team confirms that the switch does NOT support ip helper-address pointing to the ISE PSN, and they will not add a second helper. Which probe should the engineer enable so ISE can still collect these DHCP attributes from client traffic?

Reviewed for accuracy · Report an issue
Question 7 of 20

A network administrator wants ISE to enrich endpoint profiling data by resolving the fully qualified domain name (FQDN) associated with an endpoint's IP address. The DNS probe is enabled, but ISE is not populating the FQDN attribute for any endpoints. Which condition must be satisfied for the DNS probe to successfully collect the FQDN?

Reviewed for accuracy · Report an issue
Question 8 of 20

A network engineer notices that ISE is generating a very high volume of profiler-related database updates, causing replication load between the PAN and PSNs. Investigation shows that endpoints are constantly sending updated DHCP and RADIUS attributes that only marginally change the endpoint records, with no impact on profile classification. Which profiler configuration option should the engineer enable to reduce this unnecessary replication and persistence overhead?

Reviewed for accuracy · Report an issue
Question 9 of 20

A network administrator has created a custom endpoint identity group named "Corporate-Tablets" in ISE. They manually add several tablet MAC addresses to this group through the Endpoints page. The profiler policy for these tablets is configured to match the built-in "Apple-iPad" profile, which is mapped to a different endpoint identity group. After profiling runs, the administrator notices the manually added tablets remain in the "Corporate-Tablets" group and are NOT reassigned to the Apple-iPad group. What explains this behavior?

Reviewed for accuracy · Report an issue
Question 10 of 20

A network administrator has a spreadsheet listing 200 MAC addresses for corporate IoT sensors that should be granted network access via MAB. These devices do not respond well to active probing and must be manually managed. The administrator wants to bulk-add all of these endpoints into ISE and place them into a specific endpoint identity group so an authorization policy can match them. What is the most efficient way to accomplish this in Cisco ISE?

Reviewed for accuracy · Report an issue
Question 11 of 20

A network administrator has a specialized medical device that ISE keeps profiling incorrectly as a generic Workstation because its attributes overlap with a broader profile. The administrator manually edits the endpoint in the ISE context visibility and enables the 'Static Assignment' checkbox, assigning it to a custom 'Medical-Devices' identity group. What is the effect of enabling Static Assignment on this endpoint?

Reviewed for accuracy · Report an issue
Question 12 of 20

A network administrator notices that a batch of newly deployed IoT sensors is being classified only as 'Unknown' in ISE, even though the vendor recently published matching profiling signatures. The administrator wants ISE to automatically obtain the latest device profiling definitions and OUI mappings from Cisco without manually building custom profiler policies. Which ISE profiler feature should be enabled to accomplish this?

Reviewed for accuracy · Report an issue
Question 13 of 20

An administrator wants ISE to classify endpoints such as Apple iPads and Android tablets based on the browser User-Agent string they present when redirected to a portal. Client HTTP traffic is redirected to ISE through a central web authentication flow. Which profiler probe must be enabled on the Policy Service Node to capture and use this User-Agent attribute for classification?

Reviewed for accuracy · Report an issue
Question 14 of 20

A security engineer has ISE profiling several device types: IP cameras, badge readers, and building sensors, each matching its own endpoint profiling policy. The engineer wants a single authorization rule that grants all of these IoT devices the same restricted dACL, without listing each individual profile in the authorization condition or maintaining separate rules. What is the most efficient way to accomplish this?

Reviewed for accuracy · Report an issue
Question 15 of 20

A network administrator wants ISE to profile IoT devices that reveal their identity primarily through the volume, direction, and destination patterns of their network traffic rather than through DHCP, HTTP, or SNMP attributes. The administrator plans to export flow records from border routers to ISE to support this classification. Which profiler probe should be enabled to collect this data?

Reviewed for accuracy · Report an issue
Question 16 of 20

A network administrator wants ISE to improve profiling accuracy for a group of unknown endpoints that are not sending enough passive attribute data. The administrator needs ISE to actively query these endpoints to determine their operating system and open ports, but only after an endpoint is first detected. Which profiler probe should be enabled to accomplish this active data collection?

Reviewed for accuracy · Report an issue
Question 17 of 20

A network engineer is deploying ISE profiling for a large campus. Endpoints authenticate via MAB on switches, and the engineer wants ISE to collect DHCP attributes (such as dhcp-class-identifier) without deploying an ISE anycast helper or configuring 'ip helper-address' pointing to the PSN. The switches already forward RADIUS accounting to ISE. Which probe should the engineer enable to gather these DHCP attributes with minimal additional network configuration?

Reviewed for accuracy · Report an issue
Question 18 of 20

An engineer wants ISE to profile endpoints using RADIUS accounting attributes forwarded by switches that have the IOS Device Sensor feature enabled. The switches send CDP, LLDP, and DHCP data inside RADIUS accounting packets. On the ISE Policy Service node, which probe must be enabled so ISE can parse this data and use it for profiling?

Reviewed for accuracy · Report an issue
Question 19 of 20

A network engineer wants ISE to profile endpoints without deploying SPAN sessions or additional collectors. The access switches are Catalyst devices that support IOS Device Sensor. The engineer configures Device Sensor to gather CDP, LLDP, and DHCP attributes and forward them to ISE. Which ISE probe must be enabled on the Policy Service node so these attributes are received and used for profiling?

Reviewed for accuracy · Report an issue
Question 20 of 20

A network engineer wants ISE to profile IP phones and access points more accurately. The RADIUS probe alone is not returning enough attributes, and the engineer needs ISE to actively pull CDP and LLDP cache data from switches to identify these endpoints by their neighbor-reported device information. Which profiler probe should be enabled to actively poll the switch for this data?

Reviewed for accuracy · Report an issue

More 300-715 practice

Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.

← Back to 300-715 overview