Get Full Version of the Exam
http://www.EnsurePass.com/300-208.html
Question No.91
Which two statements about MAB are true? (Choose two.)
-
It requires a preexisting database of the MAC addresses of permitted devices.
-
It is unable to control network access at the edge.
-
If MAB fails, the device is unable to fall back to another authentication method.
-
It is unable to link the IP and MAC addresses of a device.
-
It is unable to authenticate individual users.
Correct Answer: AE
Question No.92
Which 802.1x command is needed for ACL to be applied on a switch port?
-
dot1x system-auth-control
-
dot1x pae authenticator
-
authentication port-control auto
-
radius-server vsa send authentication
-
aaa authorization network default group radius
Correct Answer: D
Question No.93
Within a BYOD environment, when employees add devices using the My Devices Portal, which Identity Group does Cisco ISE add the endpoints to?
-
Registered
-
Employee
-
Guest
-
Profiled
Correct Answer: D
Question No.94
In a basic ACS deployment consisting of two servers, for which three tasks is the primary server responsible? (Choose three.)
-
configuration
-
authentication
-
sensing
-
policy requirements
-
monitoring
-
repudiation
Correct Answer: ABD
Question No.95
Which two statements about Cisco NAC Agents that are installed on clients that interact with the Cisco ISE profiler are true? (Choose two.)
-
They send endpoint data to AAA servers.
-
They collect endpoint attributes.
-
They interact with the posture service to enforce endpoint security policies.
-
They block access from the network through noncompliant endpoints.
-
They store endpoints in the Cisco ISE with their profiles.
-
They evaluate clients against posture policies, to enforce requirements.
Correct Answer: CF
Question No.96
Which three features should be enabled as best practices for MAB? (Choose three.)
-
MD5
-
IP source guard
-
DHCP snooping
-
storm control
-
DAI
-
URPF
Correct Answer: BCE
Question No.97
Which redirect-URL is pushed by Cisco ISE for posture redirect for corporate users?
-
https://ise1.cisco.com:8443/portal/gateway?sessionId=0A00023D0000003A239F78CCamp;portal=28 3258a0-e96e-11e4-a30a- 005056bf01c9amp;action=cppamp;token=a1a6ea71ea8f410c2637e11ba534379e
-
https://ise1.cisco.com:8443/portal/gateway?sessionId=0A00023D0000003A239F78CCamp;portal=28 3258a0-e96e-11e4-a30a- 005056bf01c9amp;action=cwaamp;token=a1a6ea71ea8f410c2637e11ba534379e
-
https://ise1.cisco.com:8443/portal/gateway?sessionId=0A00023D0000003A239F78CCamp;portal=28 3258a0-e96e-11e4-a30a- 005056bf01c9amp;action=mdmamp;token=a1a6ea71ea8f410c2637e11ba534379e
-
https://ise1.cisco.com:8443/portal/gateway?sessionId=0A00023D0000003A239F78CCamp;portal=28 3258a0-e96e-11e4-a30a- 005056bf01c9amp;action=drwamp;token=a1a6ea71ea8f410c2637e11ba534379e
Correct Answer: A
Question No.98
By default, how many days does Cisco ISE wait before it purges the expired guest accounts?
A. |
1 |
B. |
10 |
C. |
15 |
D. |
20 |
Correct Answer: C
Question No.99
Which three components comprise the Cisco ISE profiler? (Choose three.)
-
the sensor, which contains one or more probes
-
the probe manager
-
a monitoring tool that connects to the Cisco ISE
-
the trigger, which activates ACLs
-
an analyzer, which uses configured policies to evaluate endpoints
-
a remitter tool, which fails over to redundant profilers
Correct Answer: ABE
Question No.100
You configured wired 802.1X with EAP-TLS on Windows machines. The ISE authentication detail report shows quot;EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain.quot; What is the most likely cause of this error?
-
The ISE certificate store is missing a CA certificate.
-
The Wireless LAN Controller is missing a CA certificate.
-
The switch is missing a CA certificate.
-
The Windows Active Directory server is missing a CA certificate.
Correct Answer: A
Get Full Version of the Exam
300-208 Dumps
300-208 VCE and PDF