100%合格、売れ筋最上位300-715日本語試験材料は2023年最新のCisco練習試験合格させます [Q67-Q84]

Share

100%合格、売れ筋最上位300-715日本語試験材料は2023年最新のCisco練習試験合格させます

CCNP Security問題集で300-715日本語試験完全版問題、試験学習ガイド

質問 # 67
組織は、Cisco ISE 展開にノードを追加しており、プライマリおよびセカンダリ PAN および MnT ノードとして指定された 2 つのノードがあります。組織には 4 つの PSN もあります 管理者がこの展開にさらに 2 つの PSN を追加しようとしていますが、そのうちの 1 つを追加する際に問題が発生しています 問題は何ですか?

  • A. 新しいノードの 1 つを pxGrid ノードとして指定する必要があります
  • B. 現在の PAN は最大 4 つのノードしか追跡できません
  • C. このように構成されている場合、Cisco ISE キューブに含めることができる PSN は 5 つだけです。
  • D. 新しいノードは、展開に追加する前にプライマリに設定する必要があります

正解:C


質問 # 68
承認の変更を検証するユースケースはどれですか?

  • A. エンドポイントはゲストのデバイス登録を通じて作成されます
  • B. 承認ポリシーのエンドポイントプロファイリングポリシーが変更されました。
  • C. 認証された有線EAP対応エンドポイントが検出されました
  • D. ネットワークから切断されているエンドポイントが検出されました

正解:B

解説:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html


質問 # 69
ネットワーク上でワイヤレスゲストアクセスを構成するには何が必要ですか?

  • A. ISEですでにプロファイルされたエンドポイント
  • B. キャプティブポータルバイパスがオン
  • C. リダイレクション用のWEBAUTH ACL
  • D. Active Directoryの有効なユーザーアカウント

正解:C


質問 # 70
Cisco ISEはどのシナリオでアドバンストライセンスを割り当てますか?

  • A. 動的デバイスプロファイリング
  • B. SGA施行を使用したエンドポイント認証
  • C. 高可用性管理者ノード
  • D. dACL施行のゲストサービス

正解:B


質問 # 71
MABはMACアドレスを何に利用しますか?

  • A. password
  • B. cisco-av-pair
  • C. Calling-Station-ID
  • D. username

正解:D


質問 # 72
認証を成功させるには、不明なMACアドレス/ IDのCisco ISE認証ポリシーで何を設定する必要がありますか?

  • A. 続行
  • B. ドロップ
  • C. 拒否
  • D. 合格

正解:A

解説:
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html


質問 # 73
Cisco ISEのどのプロファイルとも一致しないエンドポイントがメンバーになるデフォルトのエンドポイントIDグループはどれですか。

  • A. プロファイル
  • B. ホワイトリスト
  • C. 不明
  • D. ブラックリスト
  • E. エンドポイント

正解:C

解説:
If you do not have a matching profiling policy, you can assign an unknown profiling policy. The endpoint is therefore profiled as Unknown. The endpoint that does not match any profile is grouped within the Unknown identity group. The endpoint profiled to the Unknown profile requires that you create a profile with an attribute or a set of attributes collected for that endpoint.
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_identities.html


質問 # 74
ユーザーがデバイスの紛失または盗難を報告した場合、デバイスがブロックされた理由に関する情報を提供しながら、デバイスがネットワークにアクセスするのを防ぐためにどのポータルを使用する必要がありますか?

  • A. ブラックリスト
  • B. BYOD
  • C. クライアントプロビジョニング
  • D. ゲスト

正解:A


質問 # 75
CoAがReAuthに対してグローバルに有効になっている場合、エンドポイントのCoAをトリガーする2つのイベントはどれですか? (2つ選択してください。)

  • A. マイデバイスポータルで紛失としてマークされたエンドポイント
  • B. Apple-DeviceからApple-iPhoneへのエンドポイントプロファイルの移行
  • C. マイデバイスポータルへのエンドポイントの追加
  • D. エンドポイントプロファイルが不明からWindows10-ワークステーションに移行
  • E. エンドポイントdACLの更新。

正解:B、D


質問 # 76
ciscoISEが作成する3つのデフォルトエンドポイントIDグループはどれですか。 (3つ選択してください)

  • A. ブラックリスト
  • B. ホワイトリスト
  • C. 不明
  • D. プロファイル
  • E. エンドポイント

正解:A、C、D

解説:
Default Endpoint Identity Groups Created for Endpoints
Cisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_010101.html#ID1678


質問 # 77
エンジニアは、Windows 10 エンドポイントのポスチャ ポリシーを構成しており、各 AD グループのユーザーが準拠するために満たす必要があるさまざまな条件を確保したいと考えています。このタスクを達成するために何をしなければなりませんか?

  • A. 各ユース ケースで AD グループを使用するようにポスチャ要件を変更し、それらの要件をポスチャ ポリシーで使用します。
  • B. ポリシー セット内の許可ポリシーを使用して、各 AD グループをそれぞれのポスチャ ポリシーでグループ化します。
  • C. AD グループごとに単純な条件を設定し、ユース ケースごとにポスチャ ポリシーで使用します。
  • D. さまざまなポリシーに必要なユーザー グループを特定し、サービス条件を作成して、それぞれをポスチャ要件にマッピングします。

正解:B


質問 # 78
組織は、Oseo ISEでのプロファイリングを改善するために、システムに新しいプロファイリングプローブを追加しています。プローブは、エンドポイントとそれらが接続されているポートに関する情報を受信するための共通のネットワーク管理プロトコルをサポートする必要があります。これを実現するには、ネットワークデバイスで何を構成する必要がありますか。ゴール?

  • A. WCCP
  • B. SNMP
  • C. ARP
  • D. ICMP

正解:D


質問 # 79
dot1x system-auth-controlコマンドは何をしますか?

  • A. ネットワークアクセススイッチが802.1xセッションを追跡しないようにします
  • B. 802.1xをグローバルに有効にします
  • C. ネットワークアクセススイッチに802.1xセッションを追跡させます。
  • D. ネットワークアクセスデバイスインターフェイスで802.1xを有効にします

正解:B

解説:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-


質問 # 80
エンジニアは、認証の成功時にエンドポイントに VLAN 310 へのアクセスを許可する新しい許可ポリシーを作成しています。 管理者は、エンドポイントの 802.1X 認証をテストし、正常に認証されていることを確認します。 VLAN?

  • A. スイッチ ポートで switchport access vlan 310 コマンドを構成します。
  • B. 認可プロファイルの共通タスクに VLAN 310 を追加します。
  • C. セキュリティ グループがエンドポイントの VLAN 310 への配置を妨げていないことを確認します。
  • D. エンドポイントが正しいポリシー セットを使用していることを確認します。

正解:B


質問 # 81
Cisco ISE分散展開に2つのノードがあり、セカンダリノードの登録が解除されるとどうなりますか。

  • A. プライマリノードが再起動します
  • B. 両方のノードが再起動します。
  • C. プライマリノードがスタンドアロンになります
  • D. セカンダリノードが再起動します。

正解:B

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ise/1-1-1/installation_guide/ise_install_guide/ise_deploy.html if your deployment has two nodes and you deregister the secondary node, both nodes in this primary-secondary pair are restarted. (The former primary and secondary nodes become standalone.)


質問 # 82
ネットワークエンジニアは、ネットワーク設計を再設計することなく、特別なタグを使用してアクセス制御を実施する必要があります。
これをスケーラブルな方法で実現するには、どの機能を構成する必要がありますか?

  • A. SGT
  • B. VLAN
  • C. RBAC
  • D. dACL

正解:A


質問 # 83
CiscoISEが作成する2つのデフォルトエンドポイントIDグループはどれですか。 (2つ選択してください)

  • A. 不明
  • B. プロファイル
  • C. エンドポイント
  • D. 許可リスト
  • E. ブロックリスト

正解:A、B

解説:
Explanation
https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide Default Endpoint Identity Groups Created for EndpointsCisco ISE creates the following five endpoint identity groups by default: Blacklist, GuestEndpoints, Profiled, RegisteredDevices, and Unknown. In addition, it creates two more identity groups, such as Cisco-IP-Phone and Workstation, which are associated to the Profiled (parent) identity group. A parent group is the default identity group that exists in the system.
Cisco ISE creates the following endpoint identity groups:
* Blacklist-This endpoint identity group includes endpoints that are statically assigned to this group in Cisco ISE and endpoints that are block listed in the device registration portal. An authorization profile can be defined in Cisco ISE to permit, or deny network access to endpoints in this group.
* GuestEndpoints-This endpoint identity group includes endpoints that are used by guest users.
* Profiled-This endpoint identity group includes endpoints that match endpoint profiling policies except Cisco IP phones and workstations in Cisco ISE.
* RegisteredDevices-This endpoint identity group includes endpoints, which are registered devices that are added by an employee through the devices registration portal. The profiling service continues to profile these devices normally when they are assigned to this group. Endpoints are statically assigned to this group in Cisco ISE, and the profiling service cannot reassign them to any other identity group.
* These devices will appear like any other endpoint in the endpoints list. You can edit, delete, and block these devices that you added through the device registration portal from the endpoints list in the Endpoints page in Cisco ISE. Devices that you have blocked in the device registration portal are assigned to the Blacklist endpoint identity group, and an authorization profile that exists in Cisco ISE redirects blocked devices to a URL, which displays "Unauthorised Network Access", a default portal page to the blocked devices.
* Unknown-This endpoint identity group includes endpoints that do not match any profile in Cisco ISE.
In addition to the above system created endpoint identity groups, Cisco ISE creates the following endpoint identity groups, which are associated to the Profiled identity group:
* Cisco-IP-Phone-An identity group that contains all the profiled Cisco IP phones on your network.
* Workstation-An identity group that contains all the profiled workstations on your network.


質問 # 84
......

正真正銘のベスト試験材料300-715日本語オンライン練習試験:https://www.goshiken.com/Cisco/300-715J-mondaishu.html