Question No: 1

Which technology performs CoA support Posture Service?

A. External root CA

B. Cisco ACS

C. Cisco ISE

D. Internal root CA

Answer: C

Question No: 2

Which command on the switch ensures that the Service-Type attribute is sent with all RADIUS authentication request?

A. radius-server attribute 8 include-in-access-req

B. radius-server attribute 25 access-request include

C. radius-server attribute 6 on-for-login-auth

D. radius-server attribute 31 send nas-port-detail

Answer: C

Question No: 3

Refer to the exhibit. Which authentication method is being used?





Answer: A


These authentication methods are supported with LDAP:

Extensible Authentication Protocol u2013 Generic Token Card (EAP-GTC) Extensible Authentication Protocol u2013 Transport Layer Security (EAP-TLS) Protected Extensible Authentication Protocol u2013 Transport Layer Security (PEAP-

Question No: 4

Which effect does the ip http secure-server command have on a Cisco ISE?

A. It enables the HTTP server for users to connect on the command line.

B. It enables the HTTP server for users to connect by using web-based authentication.

C. It enables the HTTPS server for users to connect by using web-based authentication.

D. It enables the HTTPS server for users to connect on the command line.

Answer: C

Question No: 5

Which two options are EAP methods supported by Cisco ISE? (Choose two.)





Answer: A,B

Question No: 6

Which functionality does the Cisco ISE BYOD flow provide?

A. It provides support for native supplicants, allowing users to connect devices directly to the network.

B. It provides the My Devices portal, allowing users to add devices to the network.

C. It provides support for users to install the Cisco NAC agent on enterprise devices.

D. It provides self-registration functionality to allow guest users to access the network.

Answer: A

Question No: 7

What are two possible reasons why a scheduled nightly backup of ISE to a FTP repository would fail? (Choose two.)

A. ISE attempted to write the backup to an invalid path on the FTP server.

B. The ISE and FTP server clocks are out of sync.

C. The username and password for the FTP server are invalid.

D. The server key is invalid or misconfigured.

E. TCP port 69 is disabled on the FTP server.

Answer: A,C

Question No: 8

Which option describes the purpose of configuring Native Supplicant Profile on the Cisco ISE?

A. It helps employees add and manage new devices by entering the MAC address for the device.

B. It is used to register personal devices on the network.

C. It enforces the use of MSCHAPv2 or EAP-TLS for 802.1X authentication.

D. It provides posture assessments and remediation for devices that are attempting to gain access to the corporate network.

Answer: C

Question No: 9

In an 802.1X authorization process, a network access device provides which three functions? (Choose three.)

A. Filters traffic prior to authentication

B. Passes credentials to authentication server

C. Enforces policy provided by authentication server

D. Hosts a central web authentication page

E. Confirms supplicant protocol compliance

F. Validates authentication credentials

Answer: A,B,C

Question No: 10

Which debug command on a Cisco WLC shows the reason that a client session was terminated?

A. debug dot11 state enable

B. debug dot1x packet enable

C. debug client mac addr

D. debug dtls event enable

E. debug ap enable cisco ap

Answer: C

