Default Flashcards

(31 cards)

1
Q

Which personas can a Cisco ISE node assume?

A

Administration, Policy Service, Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?

A

The secondary node restarts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Configure a Cisco ISE node as a primary administration node from the left into the correct order on the right.

A

Step 1: Choose Administration > System > Deployment.

Step 2: Select the check box next to the current node, and then click Edit.

Step 3: Click Make Primary.

Step 4: Click Save.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which two features are available when the primary admin node is down and the secondary admin node has not been promoted?

A

New AD user 802.1X authentication and Posture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which supplicant(s) and server(s) are capable of supporting EAP-CHAINING?

A

Cisco AnyConnect NAM and Cisco Identity Service Engine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a requirement for Feed Service to work?

A

Cisco ISE has Internet access to download feed update.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a method for transporting security group tags throughout the network?

A

By the Security Group Tag Exchange Protocol.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An engineer is configuring a virtual Cisco ISE deployment and needs each persona to be on a different node. Which persona should be configured with the largest amount of storage in this environment?

A

Monitoring and Troubleshooting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In a standalone Cisco ISE deployment, which two personas are configured on a node?

A

Administration and Policy service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A network engineer must enforce access control using special tags, without re-engineering the network design. Which feature should be configured to achieve this in a scalable manner?

A

SGT(Security Group Tags)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A network engineer is configuring a network device that needs to filter traffic based on security group tags using a security policy on a routed interface. Which command should be used to accomplish this task?

A

cts role-based enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In a Cisco ISE split deployment model, which load is split between the nodes?

A

AAA (Authentication, Authorization, and Accounting)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the deployment mode when two Cisco ISE nodes are configured in an environment?

A

Distributed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. From which Cisco ISE persona should this traffic be originating?

A

Policy Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does a fully distributed Cisco ISE deployment include?

A

All Cisco ISE personas on their own dedicated nodes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

An engineer is configuring 802.1X and wants it to be transparent from the users’ point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices. Which deployment mode should be used to achieve this?

17
Q

A network administrator changed a Cisco ISE deployment from pilot to production and noticed that the JVM memory utilization increased significantly. The administrator suspects this is due to replication between the nodes. What must be configured to minimize performance degradation?

A

Enable the endpoint attribute filter.

18
Q

An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate. What must be done in order to provide the CA this information?

A

Generate the CSR.

19
Q

An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as Medical Switch so that the policies can be made separately for the endpoints connecting through them. Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal?

A

Change the device type to Medical Switch.

20
Q

An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the main deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out. Which configuration is causing this behavior?

A

One of the nodes is the Primary PAN.

21
Q

A network administrator must configure Cisco ISE Personas in the company to share session information via syslog. Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?

22
Q

What is the maximum number of PSN nodes supported in a medium-sized deployment?

23
Q

How is policy services node redundancy achieved in a deployment?

A

By creating a node group

24
Q

Which two fields are available when creating an endpoint on the context visibility page of Cisco ISE?

A

Policy Assignment and Identity Group Assignment

25
In which two ways can users and endpoints be classified for TrustSec?
VLAN and dynamic
26
When configuring Active Directory groups, what does the Cisco ISE use to resolve ambiguous group names?
SID
27
Which permission is common to the Active Directory Join and Leave operations?
Search Active Directory to see if a Cisco ISE machine account already exists.
28
Which interface-level command is needed to turn on 802.1X authentication?
Dot1x pae authenticator
29
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?
Idle-timeout
30
What does the dot1x system-auth-control command do?
Globally enables 802.1x
31