An administrator is configuring a new profiling policy in Cisco ISE for a printer type that is missing from the profiler feed The logical profile Printers must be used in the authorization rule and the rule must be hit. What must be done to ensure that this configuration will be successful^
What are two requirements of generating a single signing in Cisco ISE by using a certificate provisioning portal, without generating a certificate request? (Choose two )
There is a need within an organization for a new policy to be created in Cisco ISE. It must validate that a specific anti-virus application is not only installed, but running on a machine before it is allowed access to the network. Which posture condition should the administrator configure in order for this policy to work?
What are the minimum requirements for deploying the Automatic Failover feature on Administration nodes in a distributed Cisco ISE deployment?
An employee logs on to the My Devices portal and marks a currently on-boarded device as ‘Lost’.
Which two actions occur within Cisco ISE as a result oí this action? (Choose two)
Which Cisco ISE deployment model provides redundancy by having every node in the deployment configured with the Administration. Policy Service, and Monitoring personas to protect from a complete node failure?
What sends the redirect ACL that is configured in the authorization profile back to the Cisco WLC?
Drag the Cisco ISE node types from the left onto the appropriate purposes on the right.

An engineer has been tasked with standing up a new guest portal for customers that are waiting in the lobby. There is a requirement to allow guests to use their social media logins to access the guest network to appeal to more customers What must be done to accomplish this task?
A network engineer must configure BYOD using Cisco ISE. In the deployment, the users must be able to submit CSR through the end devices. Which two features must be enabled to meet the requirement?
(Choose two.)

Refer to the exhibit Which component must be configured to apply the SGACL?
In a Cisco ISE split deployment model, which load is split between the nodes?
An administrator is responsible for configuring network access for a temporary network printer. The administrator must only use the printer MAC address 50:89:65: 18:8: AB for authentication. Which authentication method will accomplish the task?
An organization is hosting a conference and must make guest accounts for several of the speakers attending. The conference ended two days early but the guest accounts are still being used to access the network. What must be configured to correct this?
A network administrator is setting up wireless guest access and has been unsuccessful in testing client access. The endpoint is able to connect to the SSID but is unable to grant access to the guest network through the guest portal. What must be done to identify the problem?
An engineer must configure a new authorization policy in Cisco ISE for wireless users. The policy must match a specific SSID name and use standard RADIUS attributes. The Wireless LAN Controller is already configured. Which RADIUS attribute must be configured to meet the requirement?
An engineer is deploying Cisco ISE in a network that contains an existing Cisco Secure Firewall ASA. The customer requested that Cisco TrustSec be configured so that Cisco ISE and the firewall can share SGT information.
Which protocol must be configured on Cisco ISE to meet the requirement?
Which profiling probe collects the user-agent string?
An engineer is unable to use SSH to connect to a switch after adding the required CLI commands to the device to enable TACACS+. The device administration license has been added to Cisco ISE, and the required policies have been created. Which action is needed to enable access to the switch?
Which two actions occur when a Cisco ISE server device administrator logs in to a device? (Choose two)
Which two endpoint compliance statuses are possible? (Choose two.)
Which two VMware features are supported on a Cisco ISE virtual appliance? (Choose two.)
Which file extension is required when deploying Cisco ISE using a ZTP configuration file in Microsoft Hyper-V?
An engineer is enabling a newly configured wireless SSID for tablets and needs visibility into which other types of devices are connecting to it. What must be done on the Cisco WLC to provide this information to Cisco ISE9
An engineer is deploying Cisco ISE in a network that contains existing security products from Cisco and other vendors. The customer requires support for Cisco TrustSec and the sharing of security group tags and policy objects between Cisco ISE and the other production security products. Which persona type must be enabled on one of the Cisco ISE nodes?
An engineer is configuring Cisco ISE to reprofile endpoints based only on new requests of INIT-REBOOT and SELECTING message types. Which probe should be used to accomplish this task?
What service can be enabled on the Cisco ISE node to identity the types of devices connecting to a network?
An engineer must organize endpoints in a Cisco ISE identity management store to improve the operational management of IP phone endpoints. The endpoints must meet these requirements:
• classify endpoints for finance, sales, and marketing departments
• tag each endpoint as profiled
Which action organizes the endpoints?
What allows an endpoint to obtain a digital certificate from Cisco ISE during a BYOD flow?
Which controller option allows a user to switch from the provisioning SSID to the employee SSID after registration?
An organization wants to standardize the 802 1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide What must be configured to accomplish this task?
Which two task types are included in the Cisco ISE common tasks support for TACACS+ profiles?
(Choose two.)
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the mam deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out Which configuration is causing this behavior?
Which advanced option within a WLAN must be enabled to trigger Central Web Authentication for Wireless users on AireOS controller?
An engineer is working with a distributed deployment of Cisco ISE and needs to configure various network probes to collect a set of attributes from the used to accomplish this task?
An administrator is adding a switch to a network that is running Cisco ISE and is only for IP Phones The phones do not have the ability to authenticate via 802 1X Which command is needed on each switch port for authentication?
Which two external identity stores support EAP-TLS and PEAP-TLS? (Choose two.)
Drag and drop the description from the left onto the protocol on the right that is used to carry out system authentication, authentication, and accounting.

An administrator is attempting to join a new node to the primary Cisco ISE node, but receives the error message " Node is Unreachable " . What is causing this error?
Which configuration is required in the Cisco ISE authentication policy to allow Central Web Authentication?
What is a requirement for Feed Service to work?
An engineer is implementing network access control using Cisco ISE and needs to separate the traffic based on the network device ID and use the IOS device sensor capability. Which probe must be used to accomplish this task?
An engineer needs to configure Cisco ISE Profiling Services to authorize network access for IP speakers that require access to the intercom system. This traffic needs to be identified if the ToS bit is set to 5 and the destination IP address is the intercom system. What must be configured to accomplish this goal?
An administrator must change the authentication method from local accounts to SAML for wireless guest users in a Cisco ISE deployment. Using SAML, the guest portal must authenticate employees through an external identity provider. These configurations were performed:
• Created a secondary self-registered guest portal for SAML integration
• Created a primary guest portal for wireless guest users
• Configured all required settings on the SAML identity provider server
• Imported the identity provider metadata into the Cisco ISE SAML identity provider profile
Which two actions must be taken? (Choose two.)
What is needed to configure wireless guest access on the network?
A network engineer is configuring Cisco TrustSec and needs to ensure that the Security Group Tag is being transmitted between two devices Where in the Layer 2 frame should this be verified?
What is the purpose of the ip http server command on a switch?
An engineer is configuring the remote access VPN to use Cisco ISE for AAA and needs to conduct posture checks on the connecting endpoints After the endpoint connects, it receives its initial authorization result and continues onto the compliance scan What must be done for this AAA configuration to allow compliant access to the network?
An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected. Which service should be used to accomplish this task?
Profiling
Which nodes are supported in a distributed Cisco ISE deployment?
An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?
Which RADIUS attribute is used to dynamically assign the Inactivity active timer for MAB users from the Cisco ISE node?
Which two authentication protocols are supported by RADIUS but not by TACACS+? (Choose two.)
Which permission is common to the Active Directory Join and Leave operations?
What is a difference between RADIUS versus TACACS+ with regards to packet encryption?
What occurs when a Cisco ISE distributed deployment has two nodes and the secondary node is deregistered?
Refer to the exhibit.

Which two configurations are needed on a catalyst switch for it to be added as a network access device in a Cisco ISE that is being used for 802 1X authentications? (Choose two )

The IT manager wants to provide different levels of access to network devices when users authenticate using TACACS+. The company needs specific commands to be allowed based on the Active Directory group membership of the different roles within the IT department. The solution must minimize the number of objects created in Cisco ISE. What must be created to accomplish this task?
When configuring an authorization policy, an administrator cannot see specific Active Directory groups present in their domain to be used as a policy condition. However, other groups that are in the same domain are seen What is causing this issue?
An administrator is configuring the Native Supplicant Profile to be used with the Cisco ISE posture agents and needs to test the connection using wired devices to determine which profile settings are available. Which two configuration settings should be used to accomplish this task? (Choose two.)
A network administrator is configuring a secondary cisco ISE node from the backup configuration of the primary cisco ISE node to create a high availability pair The Cisco ISE CA certificates and keys must be manually backed up from the primary Cisco ISE and copied into the secondary Cisco ISE Which command most be issued for this to work?
An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?
An engineer is configuring a new Cisco ISE node. The Device Admin service must run on this node to handle authentication requests for network-device access through TACACS+. Which persona must be enabled on this node to perform this function?
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for one day When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their Workstation from the corporate network Which CoA configuration meets this requirement?

Refer to the exhibit. An engineer needs to configure central web authentication on the Cisco Wireless LAN Controller to use Cisco ISE for all guests connected to the wireless network. The components are configured already:
• Cisco Wireless LAN Controller is fully configured
• authorization profile on the Cisco ISE
• authentication policy on the Cisco ISE
Which component would be configured next on Cisco ISE?
A network engineer needs to deploy 802.1x using Cisco ISE in a wired network environment where thin clients download their system image upon bootup using PXE. For which mode must the switch ports be configured?
Which statement about configuring certificates for BYOD is true?
Refer to the exhibit.

An engineer is creating a new TACACS* command set and cannot use any show commands after togging into the device with this command set authorization Which configuration is causing this issue?
An administrator is configuring posture with Cisco ISE and wants to check that specific services are present on the workstations that are attempting to access the network. What must be configured to accomplish this goal?
An administrator for a small network is configuring Cisco ISE to provide dynamic network access to users. Management needs Cisco ISE to not automatically trigger a CoA whenever a profile change is detected. Instead, the administrator needs to verify the new profile and manually trigger a CoA. What must be configuring in the profiler to accomplish this goal?
What is a function of client provisioning?
Refer to the exhibit.

An engineer must configure the guest access settings in Cisco ISE. These configurations have already been performed:
• Configured the Wireless LAN Controller and added it as a network device in Cisco ISE.
• Created an endpoint identity group and a self-registered guest type.
• Configured SMTP and the registration form to send credentials by email.
Which two types of profiles must be configured next in Cisco ISE to meet the requirement? (Choose two.)
A customer wants to set up the Sponsor portal and delegate the authentication flow to a third party for added security while using Kerberos Which database should be used to accomplish this goal?
An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. From which Cisco ISE persona should this traffic be originating?
Refer to the exhibit.

An engineer is configuring a client but cannot authenticate to Cisco ISE During troubleshooting, the show authentication sessions command was issued to display the authentication status of each port Which command gives additional information to help identify the problem with the authentication?
A network administrator must configure Cisco SE Personas in the company to share session information via syslog. Which Cisco ISE personas must be added to syslog receivers to accomplish this goal?
Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE? (Choose two).
An engineer tests Cisco ISE posture services on the network and must configure the compliance module to automatically download and install on endpoints Which action accomplishes this task for VPN users?
An engineer must use Cisco ISE to provide network access to endpoints that cannot support 802.1X. The endpoint MAC addresses must be allowlisted by configuring an endpoint identity group. These configurations were performed:
• configured an identity group named allowlist
• configured the endpoints to use the MAC address of incompatible 802.1X devices
• added the endpoints to the allowlist identity group
• configured an authentication policy for MAB users
What must be configured?
A Cisco ISE administrator needs to ensure that guest endpoint registrations are only valid for 1 day. When testing the guest policy flow, the administrator sees that the Cisco ISE does not delete the endpoint in the Guest Endpoints identity store after one day and allows access to the guest network after that period. Which configuration is causing this problem?
Which media type must be used for zero-touch provisioning on a Cisco ISE hardware appliance?
A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA Which action does the CoA perform?
What is an advantage of TACACS+ versus RADIUS authentication when reviewing reports in Cisco ISE?
Which two external identity stores are supported by Cisco ISE for password types? (Choose two.)
An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate. What must be done in order to provide the CA this information?
An administrator must configure Cisco ISE to distribute Cisco Secure Client to Windows systems. The solution must meet these requirements:
• Users must install Cisco Secure Client before connecting to the network.
• Endpoints that do not have Cisco Secure Client installed must be redirected to the Client Provisioning Portal.
These configurations were performed:
• Enabled client provisioning
• Uploaded the Cisco Secure Client package
• Downloaded the Cisco Secure Client compliance module
• Created a native supplicant profile
• Created the Cisco Secure Client configuration
• Created the Client Provisioning Portal
• Created an authorization profile for client provisioning
• Configured authorization policies
Which two actions must be performed in Cisco ISE to distribute Cisco Secure Client and complete the configuration? (Choose two.)
Which two fields are available when creating an endpoint on the context visibility page of Cisco IS? (Choose two)
Which two Cisco ISE deployment models require two nodes configured with dedicated PAN and MnT personas? (Choose two.)
An engineer is configuring a new Cisco ISE node. Context-sensitive information must be shared between the Cisco ISE and a Cisco ASA. Which persona must be enabled?
Which three default endpoint identity groups does cisco ISE create? (Choose three)
A company is attempting to improve their BYOD policies and restrict access based on certain criteria. The company ' s subnets are organized by building. Which attribute should be used in order to gain access based on location?
An ISE administrator must change the inactivity timer for MAB endpoints to terminate the authentication session whenever a switch port that is connected to an IP phone does not detect packets from the device for 30 minutes. Which action must be taken to accomplish this task?
An administrator is editing a csv list of endpoints and wants to reprofile some of the devices indefinitely before importing the list into Cisco ISE. Which field and Boolean value must be changed for the devices before the list is reimported?
A network engineer must create a guest portal for wireless guests on Cisco ISE. The guest users must not be able to create accounts; however, the portal should require a username and password to connect. Which portal type must be created in Cisco ISE to meet the requirements?
An administrator replaced a PSN in the distributed Cisco ISE environment. When endpoints authenticate to it, the devices are not getting the right profiles or attributes and as a result, are not hitting the correct policies. This was working correctly on the previous PSN. Which action must be taken to ensure the endpoints get identified?