New Questions 8

Which operating system type needs access to the Internet to download the application that is required for BYOD on-boarding?

A. iOS


C. Android

D. Windows

Answer: C

New Questions 9

Which Cisco ISE feature can differentiate a corporate endpoint from a personal device?

A. EAP chaining

B. PAC files

C. authenticated in-band provisioning

D. machine authentication

Answer: A

New Questions 10

Which feature must you configure on a switch to allow it to redirect wired endpoints to Cisco ISE?

A. the http secure-server command

B. RADIUS Attribute 29

C. the RADIUS VSA for accounting


Answer: A

New Questions 11

Security Group Access requires which three syslog messages to be sent to Cisco ISE? (Choose three.)







Answer: B,D,F

New Questions 12

When you configure an endpoint profiling policy rule, which option describes the purpose of the minimum certainty factor?

A. It is compared to the total certainty metric of an individual endpoint to determine whether the endpoint can be trusted.

B. It is compared to the assigned certainty value of an individual endpoint in a device database to determine whether the endpoint can be trusted.

C. It is used to compare the policy condition to other active policies.

D. It is used to determine the likelihood that an endpoint is an active, trusted device on the network.

Answer: A

New Questions 13

Refer to the exhibit.

Which statement about the authentication protocol used in the configuration is true?

A. There is separate authentic and authorization request packet.

B. The authentication request contains only a password.

C. The authentication and authorization requests are grouped in a single packet.

D. The authentication request contains only a username.

Answer: B

New Questions 14

Which command can check a AAA server authentication for server group Group1, user cisco, and password cisco555 on a Cisco ASA device?

A. ASA# test aaa-server authentication Group1 username cisco password cisco555

B. ASA# test aaa-server authentication group Group1 username cisco password cisco555

C. ASA# aaa-server authorization Group1 username cisco password cisco555

D. ASA# aaa-server authentication Group1 roger cisco555

Answer: A

New Questions 15

The corporate security policy requires multiple elements to be matched in an authorization policy. Which elements can be combined to meet the requirement?

A. Device registration status and device activation status

B. Network access device and time condition

C. User credentials and server certificate

D. Built-in profile and custom profile

Answer: B

New Questions 16

Which two statements about administrative access to the ACS Solution Engine are true? (Choose two.)

A. The ACS Solution Engine supports command-line connections through a serial-port connection.

B. For GUI access, an administrative GUI user must be created with the add-guiadmin command.

C. The ACS Solution Engine supports command-line connections through an Ethernet interface.

D. An ACL-based policy must be configured to allow administrative-user access.

E. GUI access to the ACS Solution Engine is not supported.

Answer: A,B

Explanation: who possess the proper administrative credentials. The CLI administrator does not have access to the ACS web GUI.

To create an initial GUI administrator account that allows web access to the ACS SE GUI, use the add-guiadmin command to create a GUI account.

add-guiadmin :

Adds a GUI account that allows access to the SE using the ACS web GUI.

New Questions 17

During client provisioning on a Mac OS X system, the client system fails to renew its IP address. Which change can you make to the agent profile to correct the problem?

A. Enable the Agent IP Refresh feature.

B. Enable the Enable VLAN Detect Without UI feature.

C. Enable CRL checking.

D. Edit the Discovery Host parameter to use an IP address instead of an FQDN.

Answer: A

