Question No: 6

When you select Centralized Web Auth in the ISE Authorization Profile, which component hosts the web authentication portal?

A. the endpoints

B. the WLC

C. the access point

D. the switch


Answer: E

Question No: 7

A network administrator needs to determine the ability of existing network devices to deliver key BYOD services. Which tool will complete a readiness assessment and outline hardware and software capable and incapable devices?

A. Prime Infrastructure

B. Network Control System

C. Cisco Security Manager

D. Identity Services Engine

Answer: A

Question No: 8

Which two statements about administrative access to the ACS Solution Engine are true?

(Choose two.)

A. The ACS Solution Engine supports command-line connections through a serial-port connection.

B. For GUI access, an administrative GUI user must be created with the add-guiadmin command.

C. The ACS Solution Engine supports command-line connections through an Ethernet interface.

D. An ACL-based policy must be configured to allow administrative-user access.

E. GUI access to the ACS Solution Engine is not supported.

Answer: B,D

Question No: 9

Which command configures console port authorization under line con 0?

A. authorization default|WORD

B. authorization exec line con 0|WORD

C. authorization line con 0|WORD

D. authorization exec default|WORD

Answer: D

Question No: 10

Which statement about the Cisco ISE BYOD feature is true?

A. Use of SCEP/CA is optional.

B. BYOD works only on wireless access.

C. Cisco ISE needs to integrate with MDM to support BYOD.

D. Only mobile endpoints are supported.

Answer: A

Question No: 11

Where would a Cisco ISE administrator define a named ACL to use in an authorization policy?

A. In the conditions of an authorization rule.

B. In the attributes of an authorization rule.

C. In the permissions of an authorization rule.

D. In an authorization profile associated with an authorization rule.

Answer: D

Question No: 12

Which default identity source is used by the MyDevices_Portal_Sequence identity source sequence?

A. internal users

B. guest users

C. Active Directory

D. internal endpoints

E. RADIUS servers

Answer: A

Question No: 13

Refer to the exhibit.

Which statement about the authentication protocol used in the configuration is true?

A. There is separate authentic and authorization request packet.

B. The authentication request contains only a password.

C. The authentication and authorization requests are grouped in a single packet.

D. The authentication request contains only a username.

Answer: B

Question No: 14

A user configured a Cisco Identity Service Engine and switch to work with downloadable access list for wired dot1x users, though it is failing to work. Which command must be added to address the issue?

A. ip dhcp snooping

B. ip device tracking

C. dot1x pae authenticator

D. aaa authentication dot1x default group radius

Answer: B

Question No: 15

Which two components are required to connect to a WLAN network that is secured by EAP-TLS authentication? (Choose two.)

A. Kerberos authentication server

B. AAA/RADIUS server


D. CA server

Answer: B,D

