300-208 Exam - SISAS Implementing Cisco Secure Access Solutions (SISAS)

certleader.com

P.S. Best Quality 300-208 testing engine are available on Google Drive, GET MORE: https://drive.google.com/open?id=1aY4pDbWZ7AXlcWC8JOtTYpBXA2BxqKaW


New Cisco 300-208 Exam Dumps Collection (Question 6 - Question 15)

Q1. Which command defines administrator CLI access in ACS5.x?

A. Application reset-passwd acs username

B. username username password password role admin

C. username username password plain password role admin

D. password-policy

Answer: C


Q2. CORRECT TEXT

Prime Uses Which protocol for devices discovery ?

Answer:

RARP,LLDP


Q3. Which EAP method uses a modified version of the MS-CHAP authentication protocol?

A. EAP-POTP

B. EAP-TLS

C. LEAP

D. EAP-MD5

Answer: C


Q4. Which three statements describe differences between TACACS+ and RADIUS? (Choose three.)

A. RADIUS encrypts the entire packet, while TACACS+ encrypts only the password.

B. TACACS+ encrypts the entire packet, while RADIUS encrypts only the password.

C. RADIUS uses TCP, while TACACS+ uses UDP.

D. TACACS+ uses TCP, while RADIUS uses UDP.

E. RADIUS uses ports 1812 and 1813, while TACACS+ uses port 49.

F. TACACS+ uses ports 1812 and 1813, while RADIUS uses port 49

Answer: B,D,E


Q5. A network administrator must enable which protocol to utilize EAP-Chaining?

A. EAP-FAST

B. EAP-TLS

C. MSCHAPv2

D. PEAP

Answer: A


Q6. A network administrator is seeing a posture status "unknown" for a single corporate machine on the Cisco ISE authentication report, whereas the other machines are reported as "compliant". Which option is the reason for machine being reported as "unknown"?

A. Posture agent is not installed on the machine.

B. Posture policy does not support the OS.

C. Posfure compliance condition is missing on the machine.

D. Posture service is disabled on Cisco ISE.

Answer: A


Q7. Which five portals are provided by PSN? (Choose five.)

A. guest

B. sponsor

C. my devices

D. blacklist

E. client provisioning

F. admin

G. monitoring and troubleshooting

Answer: A,B,C,D,E


Q8. When RADIUS NAC and AAA Override are enabled for a WLC on a Cisco ISE, which two statements about RADIUS NAC are true? (Choose two.)

A. It returns an access-accept and sends the redirection URL for all users.

B. It establishes secure connectivity between the RADIUS server and the Cisco ISE.

C. It allows the Cisco ISE to send a CoA request that indicates when the user is authenticated.

D. It is used for posture assessment, so the Cisco ISE changes the user profile based on posture result.

E. It allows multiple users to authenticate at the same time.

Answer: C,D


Q9. Which advanced authentication setting is needed to allow an unknown device to utilize Central WebAuth?

A. If Authentication failed > Continue

B. If Authentication failed > Drop

C. If user not found > Continue

D. If user not found > Reject

Answer: C


Q10. What steps must you perform to deploy a CA-signed identify certificate on an ISE device?

A. 1. Download the CA server certificate.2. Generate a signing request and save it as a file.3. Access the CA server and submit the ISE request.4. Install the issued certificate on the ISE.

B. 1. Download the CA server certificate.2. Generate a signing request and save it as a file.3. Access the CA server and submit the ISE request.4. Install the issued certificate on the CA server.

C. 1. Generate a signing request and save it as a file.2. Download the CA server certificate.3. Access the ISE server and submit the CA request.4. Install the issued certificate on the CA server.

D. 1. Generate a signing request and save it as a file.2. Download the CA server certificate.3. Access the CA server and submit the ISE request.4. Install the issued certificate on the ISE.

Answer: A


100% Renewal Cisco 300-208 Questions & Answers shared by Certleader, Get HERE: https://www.certleader.com/300-208-dumps.html (New 310 Q&As)