Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) · Domain 3 · 15% of exam

Web Auth and Guest Services

Drill 20 practice questions focused entirely on Web Auth and Guest Services for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A network engineer is deploying Central Web Authentication (CWA) on a Catalyst switch running IOS. Endpoints authenticate via MAB, and ISE returns an authorization result containing a redirect URL and a redirect ACL. However, after connecting, test endpoints receive an IP address but the browser never displays the ISE guest portal — the redirection simply times out. RADIUS accounting and the CoA are confirmed working. Which switch configuration step is most likely missing and required for the redirect to function?

Reviewed for accuracy · Report an issue
Question 2 of 20

A network engineer is building a guest access solution on Cisco ISE. When an unauthenticated endpoint connects to the guest SSID, the switch/WLC must redirect the user's browser to the ISE guest portal for self-registration. The engineer is configuring the authorization profile that will be returned for these initial guest connections. Which combination of settings must the authorization profile contain to force the browser redirection to the ISE guest portal?

Reviewed for accuracy · Report an issue
Question 3 of 20

A network engineer deploys Central Web Authentication (CWA) for guests on a Cisco Catalyst switch integrated with ISE. After a guest successfully authenticates on the guest portal, ISE must instruct the switch to remove the pre-auth redirect and apply the final guest DACL without disconnecting the endpoint's link. Which mechanism must be configured on the switch and used by ISE to accomplish this transition?

Reviewed for accuracy · Report an issue
Question 4 of 20

A network engineer is deploying Central Web Authentication (CWA) for guest wireless users on a remote-site Cisco WLC where the APs operate in FlexConnect mode with local switching. Wired traffic from these APs does not traverse the WLC. Guests connect to an open SSID, associate via MAB, and are supposed to be redirected to the ISE guest portal. However, users associate but never receive the redirect. What must the engineer configure on the WLC to make the CWA redirection work in this FlexConnect local-switching scenario?

Reviewed for accuracy · Report an issue
Question 5 of 20

A network engineer configured Central Web Authentication (CWA) on ISE for wireless guests. When guests connect and are redirected to the guest portal, their browsers display a certificate warning stating the certificate name does not match the site. The engineer confirmed the WLC redirect is working and the portal loads after the guest clicks past the warning. What is the BEST way to eliminate the certificate warning?

Reviewed for accuracy · Report an issue
Question 6 of 20

A retail company runs a self-registered guest portal on ISE. Compliance requires that returning guests must re-accept the Acceptable Use Policy (AUP) every single time they log in through the portal, rather than only on their first login. Which portal setting should the administrator configure to meet this requirement?

Reviewed for accuracy · Report an issue
Question 7 of 20

A network engineer is configuring a credentialed guest portal on ISE for a corporate lobby. Contractors who already exist in the company's Active Directory should be able to log in with their AD credentials, while short-term visitors will use sponsor-created guest accounts. Under the portal's Authentication settings, which configuration ensures both account types can authenticate through the same guest portal?

Reviewed for accuracy · Report an issue
Question 8 of 20

A network administrator has deployed a Sponsored-Guest portal on ISE PSNs that are reachable at guest.company.com. During testing, guests connecting from the CWA redirect see a browser certificate warning when the portal loads, even though a valid, CA-signed wildcard certificate for *.company.com is already installed on the PSNs. The certificate is currently tagged only for EAP Authentication and Admin usage. What must the administrator do to resolve the certificate warning on the guest portal?

Reviewed for accuracy · Report an issue
Question 9 of 20

A company operates offices in Montreal, Frankfurt, and Tokyo. The security team wants a single self-registered guest portal on ISE that automatically presents the login page, AUP, and notification text in the guest's preferred language based on their browser settings, while also displaying the corporate logo. Which ISE portal configuration approach meets this requirement with the least administrative overhead?

Reviewed for accuracy · Report an issue
Question 10 of 20

A retail company wants returning guests to authenticate to the guest WiFi only once per device without re-entering credentials on subsequent visits, while still requiring initial credential entry and AUP acceptance. The security team is configuring the Self-Registered Guest Portal on ISE. Which portal setting must be enabled to meet this requirement?

Reviewed for accuracy · Report an issue
Question 11 of 20

A retail company uses ISE self-registered guest access. Marketing wants returning guests who registered last month to NOT have to re-register when they visit again this week, but the security team requires that stale guest endpoints be automatically removed after 30 days of inactivity to keep the endpoint database clean. As the ISE administrator, which configuration approach satisfies both requirements?

Reviewed for accuracy · Report an issue
Question 12 of 20

A retail company runs a self-registered guest portal on ISE. Management complains that a single guest account username and password is being shared among many customers, allowing far more devices online than intended. The security team wants each guest account to be usable on no more than two devices at the same time, while still allowing legitimate guests to register normally. Which ISE guest portal configuration should the administrator adjust to enforce this?

Reviewed for accuracy · Report an issue
Question 13 of 20

A retail company has deployed a self-registered guest portal on Cisco ISE. After guests successfully authenticate, the marketing team wants every guest browser to be automatically redirected to the company's promotional landing page (https://promo.retailco.com) rather than back to the URL the guest originally requested. Which guest portal setting must the administrator configure to achieve this behavior?

Reviewed for accuracy · Report an issue
Question 14 of 20

A retail company deploys a self-registered guest portal on ISE. Management requires that guests create their own accounts, but no guest should be able to access the internet until an employee reviews and approves the account. Additionally, the approving employee must be able to see the guest's company name and reason for visit when deciding whether to approve. Which combination of portal settings satisfies all requirements?

Reviewed for accuracy · Report an issue
Question 15 of 20

A retail company uses ISE self-registered guest access. Management requires that guest accounts automatically become inactive exactly 8 hours after the guest's FIRST successful login, regardless of when the account was created earlier in the day. Which guest Time Profile setting should the administrator configure to meet this requirement?

Reviewed for accuracy · Report an issue
Question 16 of 20

A network engineer deploys Central Web Authentication with a Cisco WLC. After a guest successfully authenticates on the ISE guest portal, the authorization result assigns the endpoint to a different VLAN than the one used during the redirect. Users report that after login, their browsers hang and their sessions eventually time out because the client keeps its original IP address, which is no longer valid on the new VLAN. Which guest portal setting should the engineer enable to resolve this issue?

Reviewed for accuracy · Report an issue
Question 17 of 20

A retail company uses ISE self-registered guest access. Security requires that guest accounts remain valid only during a visitor's stay and that the sponsor be able to immediately terminate active guest sessions when a visitor leaves early. Which sponsor portal capability must be enabled in the sponsor group settings to meet the requirement of immediately terminating an active guest's network access?

Reviewed for accuracy · Report an issue
Question 18 of 20

A retail company wants sponsors to create guest accounts at the front desk, but management requires that guest credentials be delivered directly to each visitor's mobile phone rather than being displayed on the sponsor's screen or printed. The sponsor portal is already functional. Which configuration in ISE enables this delivery method?

Reviewed for accuracy · Report an issue
Question 19 of 20

A retail company wants to provide visitors with immediate Internet access from their store WLAN. Business requirements state that guests must NOT be asked to register or enter any username and password, but they MUST accept an Acceptable Use Policy before browsing. Which ISE guest portal type should the administrator deploy to satisfy these requirements?

Reviewed for accuracy · Report an issue
Question 20 of 20

A network engineer is designing guest access for a campus with Cisco Catalyst switches and ISE. The security team requires that all guest credentials be validated centrally on ISE, that ISE dynamically push the redirect URL and a downloadable ACL to the switch after MAB, and that no web portal be hosted on the switch itself. Which web authentication method should the engineer configure to meet these requirements?

Reviewed for accuracy · Report an issue

More 300-715 practice

Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.

← Back to 300-715 overview