exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 65 discussion

Actual exam question from Cisco's 300-715
Question #: 65
Topic #: 1
[All 300-715 Questions]

An engineer is using profiling to determine what access an endpoint must receive. After configuring both Cisco ISE and the network devices for 802.1X and profiling, the endpoints do not profile prior to authentication.
What are two reasons this is happening? (Choose two.)

  • A. Closed mode is restricting the collection of the attributes prior to authentication.
  • B. The HTTP probe is malfunctioning due to closed mode being enabled.
  • C. The SNMP probe is not enabled.
  • D. NetFlow is not enable on the switch, so the attributes will not be collected.
  • E. The switch is collecting the attributes via RADIUS but the probes are not sending them.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tururu1496
Highly Voted 1 year, 8 months ago
Selected Answer: AE
The question states that both devices are configured, so we can assume that A is correct as the device might have not be profiled yet. E seems more correct answer from the list.
upvoted 7 times
...
327c7c8
Most Recent 4 days, 23 hours ago
Selected Answer: AB
agree with XBfoundX
upvoted 1 times
...
NikoTomas
4 months, 2 weeks ago
A & C A) Closed Mode is restricting communication – NAD’s Device Sensor and ISE Probes can’t obtain any profiling data from endpoint prior to authentication. C) SNMP Probe - ISE uses SMTP Probe to retrieve CPD obtained data from NAD's Device Sensor. The 802.1X closed port accepts only EAP, CDP and STP packets. So CDP is the way how NAD can get profiling information about connected host prior to its authentication and SNMP is the way how ISE retrieves it .
upvoted 1 times
NikoTomas
4 months, 2 weeks ago
SNMP, not SMTP, sorry for typo
upvoted 1 times
...
...
XBfoundX
9 months ago
For me the answer are A and B. E does not have much sense, the probe are configured so that the PSNs can get infos based on the protocol that you activate, in this case is saying that the switch is collecting the attribute but the probes are not sending them?.... That not make much sense cause we have to answers we need to understand that for sure closed mode is restricting the collection of the attributes prior to authentication, and cause there is closed mode activated the http probe is not functioning well cause the NAD device can't send the http user agent field to ISE for profiling the endpoint. This is my idea, let me know if for u it's fine
upvoted 4 times
...
denverfly
1 year, 1 month ago
Selected Answer: AC
The correct answers: Closed mode is restricting the collection of the attributes prior to authentication. When closed mode is enabled, Cisco ISE will only collect attributes from endpoints that have successfully authenticated. This can prevent Cisco ISE from collecting attributes from endpoints that are not yet authenticated, such as during the initial 802.1X handshake. The SNMP probe is not enabled. The SNMP probe is used by Cisco ISE to collect attributes from endpoints. If the SNMP probe is not enabled, Cisco ISE will not be able to collect any attributes from endpoints. The other options are incorrect
upvoted 1 times
NikoTomas
4 months, 2 weeks ago
CORRECT, but let's explain why SNMP Probe (C) is correct - because ISE uses SMTP Probe to retrieve CPD obtained data from NAD's Device Sensor. The 802.1X closed port accepts only EAP, CDP and STP packets. So this is the way how ISE can get profiling information about connected host prior to its authentication.
upvoted 1 times
...
...
THEODORABLE
1 year, 1 month ago
Selected Answer: AB
A & B seem to be most likely;
upvoted 4 times
...
DeviantSpy
1 year, 2 months ago
Selected Answer: AE
I think it is A and E.
upvoted 1 times
...
Russ
1 year, 7 months ago
The question states that both the switch and ISE are configured for profiling, which implies that probes are enabled and the switch is configured properly. This, in theory, rules out C and D. E just looks wrong to me as the probes collect rather than send. If closed mode is enabled, both A and B could then be true and would not be a result of profiling not being configured properly.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago