exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 61 discussion

Actual exam question from Cisco's 300-715
Question #: 61
Topic #: 1
[All 300-715 Questions]

An organization has a fully distributed Cisco ISE deployment. When implementing probes, an administrator must scan for unknown endpoints to learn the IP-to-
MAC address bindings. The scan is complete on one PSN, but the information is not available on the others.
What must be done to make the information available?

  • A. Cisco ISE must be configured to learn the IP-MAC binding of unknown endpoints via RADIUS authentication, not via scanning.
  • B. Cisco ISE must learn the IP-MAC binding of unknown endpoints via DHCP profiling, not via scanning.
  • C. Scanning must be initiated from the MnT node to centrally gather the information.
  • D. Scanning must be initiated from the PSN that last authenticated the endpoint.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
iceise
Highly Voted 2 years, 5 months ago
Selected Answer: D
Question is about scanning unknown endpoints. https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/reorg/b_endpoint_profiling_2_4.html#concept_57A4A7ADE3DA429A821900C5CBEA8BF0 Given below is additional information related to the manual NMAP scan results: • To detect unknown endpoints, NMAP should be able to learn the IP/MAC binding via NMAP or a supporting SNMP scan. • ISE learns IP/MAC binding of known endpoints via Radius authentication or DHCP profiling. • The IP/MAC bindings are not replicated across PSN nodes in a deployment. Therefore, you must trigger the manual scan from the PSN, which has the IP/MAC binding in its local database (for example, the PSN against which a mac address was last authenticated with). • The NMAP scan results do not display any information related to an endpoint that NMAP had previously scanned, manually or automatically.
upvoted 8 times
...
26acfae
Most Recent 6 months ago
If the endpoint is unknown, how can it be previously auhtenticated in a PSN? the correct is A
upvoted 1 times
...
XBfoundX
1 year, 6 months ago
The correct answer is D: The most recent network scan results are stored in Work Centers > Profiler > Manual Scans > Manual NMAP Scan Results. The Manaul NMAP Scan Results page displays only the most recent endpoints that are detected, along with their associated endpoint profiles, their MAC addresses, and their static assignment status as the result of a manual network scan you perform on any subnet. This page allows you to edit points that are detected from the endpoint subnet for better classification, if required. Cisco ISE allows you to perform the manual network scan from the Policy Service nodes that are enabled to run the profiling service. You must choose the Policy Service node from the primary Administration ISE node user interface in your deployment to run the manual network scan from the Policy Service node. During the manual network scan on any subnet, the Network Scan probe detects endpoints on the specified subnet, their operating systems, and check UDP ports 161 and 162 for an SNMP service.
upvoted 1 times
XBfoundX
1 year, 6 months ago
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_cisco_ise_endpoint_profiling_policies.html
upvoted 1 times
...
...
Han2022
1 year, 8 months ago
Answer is D To detect unknown endpoints, NMAP should be able to learn the IP/MAC binding via NMAP or a supporting SNMP scan. ISE learns IP/MAC binding of known endpoints via Radius authentication or DHCP profiling. The IP/MAC bindings are not replicated across PSN nodes in a deployment. Therefore, you must trigger the manual scan from the PSN, which has the IP/MAC binding in its local database (for example, the PSN against which a mac address was last authenticated with).
upvoted 1 times
...
Leogxn
1 year, 9 months ago
Selected Answer: C
Since the question states that "an administrator must scan for unknown endpoints", means we are looking for an answer related to scan so only the C or D could be the answer. If D is incorrect, the answer is C
upvoted 1 times
...
denverfly
1 year, 10 months ago
Selected Answer: C
The answer is - Scanning must be initiated from the MnT node to centrally gather the information. The Management and Monitoring (MnT) node is the central point for collecting data from all the Policy Service Nodes (PSNs) in a distributed Cisco ISE deployment. When scanning for unknown endpoints, the MnT node will send the request to the PSNs, which will perform the scanning process and send the results back to the MnT node. The MnT node will then centrally gather and distribute the information to all the PSNs. The other options are incorrect
upvoted 1 times
...
THEODORABLE
1 year, 11 months ago
Selected Answer: D
D is my choice
upvoted 2 times
...
zsrite
2 years, 2 months ago
Answer is D. The MnT node is responsible for monitoring and troubleshooting the network and collecting data from the Policy Service Nodes (PSNs). It is the central point where information from all PSNs is collected, and from where the administrator can initiate and manage various monitoring and troubleshooting tasks. When the scan for unknown endpoints is initiated, the MnT node will send the request to the PSNs, which will perform the scanning process and send the results back to the MnT node. The MnT node will then centrally gather and distribute the information to all the PSNs, making it available to the entire deployment.
upvoted 3 times
zsrite
2 years, 2 months ago
Answer is C. The MnT node is responsible for monitoring and troubleshooting the network and collecting data from the Policy Service Nodes (PSNs). It is the central point where information from all PSNs is collected, and from where the administrator can initiate and manage various monitoring and troubleshooting tasks. When the scan for unknown endpoints is initiated, the MnT node will send the request to the PSNs, which will perform the scanning process and send the results back to the MnT node. The MnT node will then centrally gather and distribute the information to all the PSNs, making it available to the entire deployment.
upvoted 1 times
...
...
[Removed]
2 years, 6 months ago
Based on this link and paragraphs, endpoint information is not replicated to other PSNs, each PSN has to profile its endpoints and stores information in a local database. Given below is additional information related to the manual NMAP scan results: To detect unknown endpoints, NMAP should be able to learn the IP/MAC binding via NMAP or a supporting SNMP scan. ISE learns IP/MAC binding of known endpoints via Radius authentication or DHCP profiling. The IP/MAC bindings are not replicated across PSN nodes in a deployment. Therefore, you must trigger the manual scan from the PSN, which has the IP/MAC binding in its local database (for example, the PSN against which a mac address was last authenticated with). The NMAP scan results do not display any information related to an endpoint that NMAP had previously scanned, manually or automatically. https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/reorg/b_endpoint_profiling_2_4.html
upvoted 2 times
...
[Removed]
2 years, 6 months ago
Selected Answer: D
The Answer is D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago