Cisco CCNP 300-715 SISE Certification Exam
Cisco Certified Specialist - Security Identity Management Implementation 300-715
The Cisco CCNP 300-715 SISE certification validates skills in implementing and configuring Cisco Identity Services Engine. The exam covers architecture and deployment, policy enforcement, web auth and guest services, profiler, BYOD, endpoint compliance, and network access device administration. Candidates demonstrate knowledge of ISE personas, Active Directory and LDAP identity stores, wired and wireless 802.1X with IBNS 2.0, MAB, TrustSec, authorization policies, guest and sponsor portals, profiling probes and CoA, BYOD onboarding, posture services, and TACACS+ device administration. The exam consists of 100 questions over 90 minutes, with an 80% passing score.
Certification Overview
- Exam name: CCNP 300-715 SISE
- Vendor: Cisco
- Exam code: 300-715
- Duration: 90 minutes
- Total questions: 100
- Passing score: 80%
Who Should Take This Exam?
Security Engineer, Network Security Engineer, ISE Administrator, Network Administrator, Systems Engineer, SOC Analyst, Security Consultant, Network Architect
Prerequisites
No formal prerequisite. Cisco recommends three to five years of networking and security experience, with hands-on work deploying and operating Cisco Identity Services Engine. Passing this exam with the SCOR 350-701 core exam earns CCNP Security.
Topics Covered
- Architecture and Deployment
- Policy Enforcement
- Web Auth and Guest Services
- Profiler
- BYOD
- Endpoint Compliance
- Network Access Device Administration
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- Drag and Drop
- Scenario-Based
CCNP 300-715 SISE Practice Questions
Our question bank contains 852+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Architecture and Deployment
In a deployment, how is redundancy for policy service nodes established?
- by enabling VIP
- by utilizing RADIUS server list on the NAD
- by creating a node group
- by deploying both primary and secondary node
What happens in a two-node Cisco ISE distributed deployment if the secondary node is deregistered?
- The primary node restarts
- The secondary node restarts.
- The primary node becomes standalone
- Both nodes restart.
What two features remain available when the primary admin node is down and the secondary node hasn’t been promoted?
- hotspot
- new AD user 802.1X authentication
- posture
- BYOD
- guest AUP
Policy Enforcement
Which interface-level command is needed to turn on 802 1X authentication?
- Dot1x pae authenticator
- dot1x system-auth-control
- authentication host-mode single-host
- aaa server radius dynamic-author
-Which permission is common to the Active Directory Join and Leave operations?
- Create a Cisco ISE machine account in the domain if the machine account does not already exist
- Remove the Cisco ISE machine account from the domain
- Set attributes on the Cisco ISE machine account
- Search Active Directory to see if a Cisco ISE machine account already exsts.
Which term refers to an endpoint agent that tries to join an 802 1X-enabled network?
- EAP server
- supplicant
- client
- authenticator
Web Auth and Guest Services
A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group. Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?
- Keep track of guest user activities
- Configure authorization settings for guest users
- Create and manage guest user accounts
- Authenticate guest users to Cisco ISE
Which two methods should a sponsor select to create bulk guest accounts from the sponsor portal?
- Random
- Monthly
- Daily
- Imported
- Known
-What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?
- Cisco-av-pair
- Class attribute
- Event
- State attribute
Profiler
-Which use case validates a change of authorization?
- An authenticated, wired EAP-capable endpoint is discovered
- An endpoint profiling policy is changed for authorization policy.
- An endpoint that is disconnected from the network is discovered
- Endpoints are created through device registration for the guests
Which default endpoint identity group does an endpoint that does not match any profile in Cisco ISE become a member of?
- Endpoints
- unknown
- blocked list
- allowed list
- profiled
Which two ports do network devices typically use for CoA?
- 443
- 19005
- 8080
- 3799
- 1700
BYOD
-Which port does Cisco ISE use for native supplicant provisioning of a Windows laptop?
- TCP 8909
- TCP 8905
- CUDP 1812
- TCP 443
During BYOD flow, from where does a Microsoft Windows PC download the Network Setup Assistant?
- Cisco App Store
- Microsoft App Store
- Cisco ISE directly
- Native OTA functionality
Which protocol must be allowed for a BYOD device to access the BYOD portal?
- HTTP
- SMTP
- HTTPS
- SSH
Endpoint Compliance
What portal allows customization of login settings for a user to access and download the compliance module?
- Client Profiling
- Client Endpoint
- Client Provisioning
- Client Guest
What two elements make up the posture requirement when setting up Cisco ISE posture?
- updates
- remediation actions
- Client Provisioning portal
- conditions
- access policy
What Cisco ISE service lets an engineer verify endpoint compliance before network connection?
- personas
- qualys
- nexpose
- posture
Network Access Device Administration
Which two features must be used on Cisco ISE to enable the TACACS feature?
- Device Administration License
- Server Sequence
- Command Sets
- Enable Device Admin Service
- External TACACS Servers
What are two benefits of TACACS+ versus RADIUS for device administration?
- TACACS+ supports 802.1X, and RADIUS supports MAB
- TACACS+ uses UDP, and RADIUS uses TCP
- TACACS+ has command authorization, and RADIUS does not
- TACACS+ provides the service type, and RADIUS does not
- TACACS+ encrypts the whole payload, and RADIUS encrypts only the password.
What configuration needs to align between Cisco ISE and the network access device for endpoint authentication to succeed?
- SNMP version
- shared secret
- certificate
- profile
Frequently Asked Questions
How many questions are on the exam?
The CCNP 300-715 SISE exam contains 100 questions.
What is the passing score?
You need 80% to pass.
How long is the exam?
You have 90 minutes to complete the exam.
More Cisco Practice Exams
- Cisco CCST 100-150 Networking Certification Exam
- Cisco CCST 100-160 Cybersecurity Certification Exam
- Cisco CCNA 200-201 CCNACBR Certification Exam
- Cisco CCNA 200-301 Certification Exam
- Cisco CCNP 300-410 ENARSI Certification Exam
- Cisco CCNP 300-710 SNCF Certification Exam
- Cisco CCNP 350-401 ENCOR Certification Exam
- Cisco CCNP 350-501 SPCOR Certification Exam
- Cisco CCNP 350-701 SCOR Certification Exam
Practice with realistic mock exams to prepare for your Cisco certification.