exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 63 discussion

Actual exam question from Cisco's 300-715
Question #: 63
Topic #: 1
[All 300-715 Questions]

An administrator is troubleshooting an endpoint that is supposed to bypass 802.1X and use MAB. The endpoint is bypassing 802.1X and successfully getting network access using MAB, however the endpoint cannot communicate because it cannot obtain an IP address.
What is the problem?

  • A. The endpoint is using the wrong protocol to authenticate with Cisco ISE.
  • B. The 802.1X timeout period is too long.
  • C. The DHCP probe for Cisco ISE is not working as expected.
  • D. An ACL on the port is blocking HTTP traffic.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wowako
7 months, 1 week ago
Based on numerous deployment experiences, the recommendation is to set the tx-period value to 10 seconds to provide the most optimal time for MAB devices. Setting the value below 10 seconds may result in unwanted behavior, and setting the value greater than 10 seconds may result in DHCP timeouts. Therefore, the answer is B Cisco ISE 300-715 - Official Cert Guide Page 275 "Configure Authentication Timers"
upvoted 3 times
...
fabio3wz
9 months, 3 weeks ago
I cannot believe some answers here... "The RADIUS server then authenticates the user and returns an IP address to the endpoint" --what's that? ISE using HTTP? ISE sending IP addresses?? That doesn't make any sense... B is the most viable answer: if dot1x timeout is too long, and therefore, MAB triggers only after that time, the client might have stopped requesting IP Address
upvoted 2 times
...
XBfoundX
1 year, 6 months ago
The only answer that make sense here is B. HTTP traffic is blocked... Who cares, i need to use DHCP ports so that do not matters. What I think is that the switchport have both 802.1x and MAB configured. So the client is sending an DHCP request but because the 802.1x timeout timer is too long the client is not getting the IP address at first, after that timeout time now the user can be authenticate via MAB, so you see that the user is authenticated but is failing to get the ip address.
upvoted 3 times
...
Leogxn
1 year, 9 months ago
Selected Answer: D
Since the issue is "the device cannot obtain an IP address", we will be focusing on how the IP obtain mechanism was blocked. A is related to authentication (The endpoint is successfully getting the network access) B 802.1X (The endpoint is bypassing 802.1X) C DHCP probe is not working (In this case, all the endpoint that using MAB should be losing communication D will be the answer as per the commend by @denverfly below
upvoted 1 times
...
denverfly
1 year, 10 months ago
Selected Answer: D
The correct answer is - An ACL on the port is blocking HTTP traffic. When an endpoint uses MAB to authenticate, it sends a username and password to the RADIUS server. The RADIUS server then authenticates the user and returns an IP address to the endpoint. If an ACL on the port is blocking HTTP traffic, the endpoint will not be able to contact the RADIUS server to authenticate and obtain an IP address. The other options are incorrect: The endpoint is using the correct protocol to authenticate with Cisco ISE. MAB is a valid authentication protocol for Cisco ISE. The 802.1X timeout period is not relevant in this case. The endpoint is bypassing 802.1X and using MAB. The DHCP probe for Cisco ISE is not relevant in this case. The endpoint is using MAB, not DHCP. Here are some things the administrator can do to troubleshoot the issue: Check the ACL on the port to make sure that HTTP traffic is not being blocked. Verify that the endpoint is configured to use MAB. Verify that the RADIUS server is configured to accept MAB authentication. Verify that the endpoint is able to contact the RADIUS server.
upvoted 3 times
Korndal
8 months, 1 week ago
So absolutely WRONG in this question what you are writing. its says that the client gets access and is accessing the correct VLAN. an ACL that blocks HTTP has no effect here, since again the client is now in the correct VLAN. But if 802.1x takes to long and then procedes to MAB then the client will not get an IP, since the client is not aware of 802.1x. So it's DHCP mechanism reaches a final timer, where it says "well nobody wants to give men an IP, so will not ask anymore"
upvoted 1 times
...
...
rhylos
1 year, 11 months ago
Selected Answer: C
When a device successfully bypasses 802.1X and authenticates using MAB (MAC Authentication Bypass), it is still required to obtain an IP address through DHCP (Dynamic Host Configuration Protocol) to communicate on the network. In this case, the fact that the endpoint cannot obtain an IP address suggests an issue with the DHCP process. The DHCP probe is a mechanism used by Cisco ISE to validate DHCP packets and ensure that the requests and responses are properly handled by the ISE infrastructure. If the DHCP probe is not functioning as expected, it can prevent DHCP traffic from reaching the DHCP server and, subsequently, hinder the endpoint from obtaining an IP address.
upvoted 2 times
...
THEODORABLE
1 year, 11 months ago
Selected Answer: B
B sound most feasible
upvoted 3 times
...
DeviantSpy
2 years ago
B is correct.
upvoted 1 times
...
gdrcar
2 years ago
Selected Answer: B
If it is too long DHCP can actually timeout
upvoted 1 times
...
Cnoteone
2 years, 1 month ago
Selected Answer: C
It's unlikely that the answer is B because the problem mentioned in the scenario is related to the endpoint not being able to obtain an IP address, which is a separate issue from the 802.1X timeout period. The 802.1X timeout period refers to how long the switch will wait for a response from the supplicant before assuming that it has failed to authenticate, so it wouldn't be related to the endpoint's ability to obtain an IP address.
upvoted 3 times
DeviantSpy
2 years ago
Some clients will stop attempting dhcp after some time, if the 802.1x timeout is longer than the clients dhcp attempts this will certainly be an issue.
upvoted 2 times
...
...
[Removed]
2 years, 6 months ago
Selected Answer: B
Correct B is the answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago