300-208 Exam - Implementing Cisco Secure Access Solutions (SISAS)

certleader.com

Q1. Which network component would issue the CoA? 

A. switch 

B. endpoint 

C. Admin Node 

D. Policy Service Node 

Answer:

Q2. Which two options are EAP methods supported by Cisco ISE? (Choose two.) 

A. EAP-FAST 

B. EAP-TLS 

C. EAP-MS-CHAPv2 

D. EAP-GTC 

Answer: A,B 

Q3. Which type of access list is the most scalable that Cisco ISE can use to implement network authorization enforcement for a large number of users? 

A. downloadable access lists 

B. named access lists 

C. VLAN access lists 

D. MAC address access lists 

Answer:

Q4. Which Cisco ISE feature can differentiate a corporate endpoint from a personal device? 

A. EAP chaining 

B. PAC files 

C. authenticated in-band provisioning 

D. machine authentication 

Answer:

Q5. Which two options are valid for configuring IEEE 802.1AE MACSec between switches in a TrustSec network? (Choose two.) 

A. manually on links between supported switches 

B. in the Cisco Identity Services Engine 

C. in the global configuration of a TrustSec non-seed switch 

D. dynamically on links between supported switches 

E. in the Cisco Secure Access Control System 

F. in the global configuration of a TrustSec seed switch 

Answer: A,D 

Q6. A network administrator needs to implement a service that enables granular control of IOS commands that can be executed. Which AAA authentication method should be selected? 

A. TACACS+ 

B. RADIUS 

C. Windows Active Directory 

D. Generic LDAP 

Answer:

Q7. You enabled the guest session limit feature on the Cisco ISE. However, end users report that the same guest can log in from multiple devices simultaneously. 

Which configuration is missing on the network access device? 

A. RADIUS authentication 

B. RADIUS accounting 

C. DHCP required 

D. AAA override 

Answer:

Q8. Which default identity source is used by the MyDevices_Portal_Sequence identity source sequence? 

A. internal users 

B. guest users 

C. Active Directory 

D. internal endpoints 

E. RADIUS servers 

Answer:

Q9. Changes were made to the ISE server while troubleshooting, and now all wireless certificate authentications are failing. Logs indicate an EAP failure. What is the most likely cause of the problem? 

A. EAP-TLS is not checked in the Allowed Protocols list 

B. Certificate authentication profile is not configured in the Identity Store 

C. MS-CHAPv2-is not checked in the Allowed Protocols list 

D. Default rule denies all traffic 

E. Client root certificate is not included in the Certificate Store 

Answer:

Q10. Which three network access devices allow for static security group tag assignment? (Choose three.) 

A. intrusion prevention system 

B. access layer switch 

C. data center access switch 

D. load balancer 

E. VPN concentrator 

F. wireless LAN controller 

Answer: B,C,E