Sign In
Home/Cisco/Implementing and Configuring Cisco Identity Services Engine (SISE 300-715)/Free questions

Implementing and Configuring Cisco Identity Services Engine (SISE 300-715) — Free Practice Questions

10 free sample questions from a bank of 425, with the correct answers and explanations. No signup required — start practising right now.

1Which personas can a Cisco ISE node assume?
  • policy service, gatekeeping, and monitoring
  • administration, monitoring, and gatekeeping
  • administration, policy service, and monitoring
  • administration, policy service, gatekeeping
Answer: C

The short version

C — An ISE node runs Administration, Policy Service, and Monitoring. Those three personas cover manage, decide, and report.

Key concepts in this question

  • Administration persona: centralized configuration and management of the deployment.
  • Policy Service persona: RADIUS/TACACS+ decisions, authentication, and authorization.
  • Monitoring (MnT) persona: logging, reports, alerts, and troubleshooting.

Why C is correct

Cisco ISE architecture defines exactly these three personas, which can run standalone on one node or distributed across nodes for scale. Administration handles GUI and config, Policy Service handles endpoint authentication sessions, and Monitoring collects logs and produces reports. Every deployment design question maps back to this trio.

Why the others are wrong

  • A. Gatekeeping is not an ISE persona; Policy Service is the correct decision-making role.
  • B. Gatekeeping is not an ISE persona; Administration plus Monitoring alone omits the Policy Service decision engine.
  • D. Gatekeeping is not an ISE persona; Monitoring is the missing third role for visibility.

300-715 exam tip — memory hook

Manage, decide, watch: Admin, Policy, MnT. Anything with gatekeeping is wrong.

2A network engineer must enforce access control using special tags, without re-engineering the network design. Which feature should be configured to achieve this in a scalable manner?
  • RBAC
  • dACL
  • SGT
  • VLAN
Answer: C

The short version

C — Use Security Group Tags for scalable tag-based access without redesign. Tags travel with traffic instead of new VLANs.

Key concepts in this question

  • Security Group Tag (SGT): TrustSec label assigned at authentication, enforced anywhere in the path.
  • Scalability: policy follows identity, not IP or topology.
  • No redesign: avoids rewiring VLANs or ACLs on every switch.

Why C is correct

SGTs let ISE classify users and devices once, embed a small tag (via inline tagging or SXP), and enforce with SGACLs downstream. That avoids re-addressing, re-VLANing, or touching every access list when roles change. The question explicitly asks for special tags without network re-engineering, which is the textbook TrustSec use case.

Why the others are wrong

  • A. RBAC controls administrator privileges on devices, not scalable data-plane segmentation by tag.
  • B. A downloadable ACL is per-session filtering pushed by ISE, useful but less scalable than tag-based enforcement across the fabric.
  • D. VLANs require topology, trunk, and addressing changes and do not scale for identity-based policy.

300-715 exam tip — memory hook

Tags without redesign equals SGT. Per-user wire filter equals dACL. Admin roles equals RBAC.

3An engineer is configuring Cisco ISE and needs to dynamically identify the network endpoints and ensure that endpoint access is protected. Which service should be used to accomplish this task?
  • guest access
  • profiling
  • posture
  • client provisioning
Answer: B

The short version

B — Profiling dynamically discovers what endpoints are and protects their access. Identity starts with visibility.

Key concepts in this question

  • Profiling service: collects DHCP, RADIUS, SNMP, NetFlow, and HTTP attributes to fingerprint devices.
  • Dynamic identification: classifies endpoints without manual entry.
  • Policy input: profile feeds authorization rules for printers, phones, and IoT.

Why B is correct

The engineer needs automatic endpoint discovery plus protected access, which is exactly ISE Profiling. Probes gather attributes continuously, match them to profiling policies, and place devices into endpoint identity groups that authorization policy can trust. No other ISE service inventories unknown endpoints this way before granting differentiated access.

Why the others are wrong

  • A. Guest access onboards visitors through portals; it does not fingerprint arbitrary network endpoints.
  • C. Posture checks endpoint compliance health after identity is known; it does not discover device types.
  • D. Client provisioning pushes agents or profiles to known clients; it does not identify unknown devices.

300-715 exam tip — memory hook

Who is that device? Profiling. Is it healthy? Posture. Onboard it? Provisioning.

4A Cisco ISE server sends a CoA to a NAD after a user logs in successfully using CWA. Which action does the CoA perform?
  • It terminates the client session.
  • It applies the downloadable ACL provided in the CoA.
  • It triggers the NAD to reauthenticate the client.
  • It applies new permissions provided in the CoA to the client session.
Answer: C

The short version

C — After Central Web Auth login, CoA triggers reauthentication. The NAD then re-authorizes with full access.

Key concepts in this question

  • Central Web Auth (CWA): redirects the client to the ISE guest portal for login.
  • Change of Authorization (CoA): RADIUS signal telling the NAD to revisit an live session.
  • Reauthentication: forces a fresh policy lookup after the portal succeeds.

Why C is correct

In the CWA flow the endpoint first gets limited redirect authorization, authenticates at the portal, and ISE sends a CoA Reauth. The NAD reauthenticates the client session, queries ISE again, and this time receives the final permit authorization. The CoA itself does not directly install permissions; it triggers the reauthentication that pulls them. That two-step sequence is core 300-715 knowledge.

Why the others are wrong

  • A. Terminate CoA ends the session and disconnects the user, the opposite of granting post-login access.
  • B. ISE does not push a dACL inside this CoA; the new authorization arrives on the subsequent reauthentication.
  • D. Applying permissions describes the eventual outcome, but the CoA action itself is the reauthentication trigger.

300-715 exam tip — memory hook

CWA equals redirect, login, CoA reauth, full access. Reauth is the bridge step.

5A new employee just connected their workstation to a Cisco IP phone. The network administrator wants to ensure that the Cisco IP phone remains online when the user disconnects their workstation from the corporate network. Which CoA configuration meets this requirement?
  • Reauth
  • Disconnect
  • No CoA
  • Port Bounce
Answer: A

The short version

A — Use Reauth CoA so the PC re-authenticates without dropping the phone. A port bounce would kill both.

Key concepts in this question

  • Reauth CoA: re-runs authentication quietly without link flap.
  • Port Bounce CoA: briefly shuts and reopens the switchport, affecting every device on it.
  • Shared port: phone with a PC daisy-chained behind it on one access port.

Why A is correct

When the workstation disconnects from behind the IP phone, ISE should only re-evaluate that session. A Reauth CoA triggers reauthentication while leaving the port up, so the phone call survives. Disconnect would needlessly terminate sessions and Port Bounce would flap power and link to the phone. Reauth is the least disruptive correct action for multi-domain or daisy-chained endpoints.

Why the others are wrong

  • B. Disconnect CoA terminates the session entirely, risking phone disruption rather than preserving it.
  • C. No CoA leaves stale authorization for the removed PC and misses the chance to re-evaluate cleanly.
  • D. Port Bounce flaps the whole physical port, dropping the phone along with the workstation.

300-715 exam tip — memory hook

Protect the phone, avoid the bounce. Reauth whispers, bounce shouts.

6An organization is adding new profiling probes to the system to improve profiling on Cisco ISE. The probes must support a common network management protocol to receive information about the endpoints and the ports to which they are connected. What must be configured on the network device to accomplish this goal?
  • ICMP
  • WCCP
  • ARP
  • SNMP
Answer: D

The short version

D — Enable SNMP on the network device for probe-driven profiling. ISE polls tables the switch already keeps.

Key concepts in this question

  • SNMPQuery and SNMPtrap probes: pull interface, MAC, CDP, and LLDP tables from NADs.
  • Common management protocol: standardized polling most switches already support.
  • Port-to-endpoint mapping: learning which MAC sits on which interface.

Why D is correct

ISE profiling probes such as SNMPQuery, SNMPtrap, and link-state collectors rely on SNMP to learn endpoint attachment, VLAN, and neighbor details from the NAD. Configuring SNMP community or v3 credentials plus traps on the switch lets ISE correlate ports with endpoints and enrich fingerprints. ICMP, WCCP, and ARP do not provide that structured management inventory.

Why the others are wrong

  • A. ICMP only tests reachability, not port inventories or device attributes.
  • B. WCCP redirects web traffic to caches or proxies, unrelated to profiling inventory.
  • C. ARP resolves IP to MAC locally but is not the managed polling protocol probes use for port data.

300-715 exam tip — memory hook

Profiling plus ports plus standard management equals SNMP.

7An administrator is trying to collect metadata information about the traffic going across the network to gain added visibility into the hosts. This information will be used to create profiling policies for devices using Cisco ISE so that network access policies can be used. What must be done to accomplish this task?
  • Configure the DHCP probe within Cisco ISE.
  • Configure NetFlow to be sent to the Cisco ISE appliance.
  • Configure the RADIUS profiling probe within Cisco ISE.
  • Configure SNMP to be used with the Cisco ISE appliance.
Answer: B

The short version

B — Send NetFlow to ISE to profile from traffic metadata. Flows reveal device behavior without agents.

Key concepts in this question

  • NetFlow probe: ingests flow records showing who talks to whom, ports, and volumes.
  • Metadata profiling: classifies devices by communication patterns.
  • Visibility first: feeds profiling policies that later drive access rules.

Why B is correct

When the goal is added visibility into hosts from traffic crossing the network, the NetFlow probe is the designed collector. Switches and routers export flow records to ISE, which extracts attributes for profiling policies. DHCP shows only boot options, RADIUS shows only authentication attributes, and SNMP shows inventory rather than traffic behavior.

Why the others are wrong

  • A. The DHCP probe fingerprints from DHCP options, not from general traffic metadata across the network.
  • C. The RADIUS probe enriches sessions with authentication attributes, not broad flow conversations.
  • D. SNMP plus ISE gathers device and port tables, not per-flow traffic metadata.

300-715 exam tip — memory hook

Traffic metadata equals NetFlow. Boot metadata equals DHCP. Auth metadata equals RADIUS.

8There are several devices on a network that are considered critical and need to be placed into the ISE database and a policy used for them. The organization does not want to use profiling. What must be done to accomplish this goal?
  • Enter the MAC address in the correct Endpoint Identity Group.
  • Enter the IP address in the correct Endpoint Identity Group.
  • Enter the IP address in the correct Logical Profile.
  • Enter the MAC address in the correct Logical Profile.
Answer: A

The short version

A — Statically add critical MAC addresses to the right Endpoint Identity Group. No profiling needed when you already trust the device.

Key concepts in this question

  • Endpoint Identity Group: static or dynamic container used directly in authorization rules.
  • MAC as identity: wired and wireless endpoints key on MAC address.
  • No profiling: manual classification for printers, controllers, and medical devices.

Why A is correct

Without profiling, the supported path is creating or choosing an Endpoint Identity Group for the critical devices and adding each MAC address as a static endpoint. Authorization policy then references that group for permit or limited access. This gives deterministic control for devices that cannot run agents or change behavior, exactly the critical-device scenario described.

Why the others are wrong

  • B. ISE endpoint identity is keyed on MAC, not IP, which changes with DHCP and cannot anchor identity.
  • C. Logical Profiles are groupings of profiling policies, not the place to register static addresses by IP.
  • D. Logical Profiles organize profiler conditions; static membership belongs in the Endpoint Identity Group by MAC.

300-715 exam tip — memory hook

No profiling, no problem: MAC into Identity Group, policy points at the group.

9An administrator is configuring a new profiling policy within Cisco ISE. The organization has several endpoints that are the same device type, and all have the same Block ID in their MAC address. The profiler does not currently have a profiling policy created to categorize these endpoints, therefore a custom profiling policy must be created. Which condition must the administrator use in order to properly profile an ACME AI Connector endpoint for network access with MAC address 01:41:14:65:50:AB?
  • CDP_cdpCacheDeviceID_CONTAINS_
  • MAC_MACAddress_CONTAINS_
  • Radius_Called_Station-ID_STARTSWITH_
  • MAC_OUI_STARTSWITH_
Answer: D

The short version

D — Match the shared vendor prefix with a MAC OUI condition. The first 24 bits are the Block ID.

Key concepts in this question

  • OUI/Block ID: first three octets identifying the manufacturer, here 01:41:14.
  • Profiling condition: attribute check such as MAC OUI STARTSWITH.
  • Custom policy: catches devices the built-in profiler does not know.

Why D is correct

All target endpoints share the same Block ID, meaning the same Organizationally Unique Identifier. A custom profiling rule using MAC_OUI STARTSWITH 01:41:14 classifies every such device regardless of the remaining host octets like 65:50:AB. That is the precise, scalable match for a single device type from one vendor.

Why the others are wrong

  • A. CDP device ID requires Cisco Discovery Protocol data the ACME connector may not send.
  • B. MAC address CONTAINS with a full address is too narrow or unpredictable for a whole device family.
  • C. Called-Station-ID reflects the NAD and port, not the endpoint vendor prefix.

300-715 exam tip — memory hook

Same Block ID equals OUI STARTSWITH. Full-MAC match is for one-offs, not fleets.

10Users in an organization report issues about having to remember multiple usernames and passwords. The network administrator wants the existing Cisco ISE deployment to utilize an external identity source to alleviate this issue. Which two requirements must be met to implement this change? (Choose two.)
  • Establish access to one Global Catalog server
  • Ensure that the NAT address is properly configured
  • Provide domain administrator access to Active Directory
  • Configure a secure LDAP connection
  • Enable IPC access over port 80
Answer: A, C

The short version

A and C — Joining Active Directory needs Global Catalog reachability and domain-admin credentials. ISE borrows logins instead of storing more passwords.

Key concepts in this question

  • External identity source: Active Directory or LDAP queried for authentication.
  • Global Catalog: forest-wide directory search service ISE relies on.
  • Domain join privilege: rights required to create the ISE computer object.

Why A and C are correct

To use Active Directory as the external identity source, ISE must reach at least one Global Catalog server for user and group lookups across the forest. Joining ISE to the domain also requires an account with domain-administrator level rights to create computer objects and establish the secure join. Together these satisfy lookup and membership, enabling single sign-on with existing credentials.

Why the others are wrong

  • B. NAT addressing is a routing concern, not an Active Directory join prerequisite.
  • D. Secure LDAP is an alternative external source, but the question targets an Active Directory join requiring catalog and privileges.
  • E. IPC over port 80 is not the required protocol set; AD join uses Kerberos, LDAP, DNS, and SMB-related services, not plain web IPC.

300-715 exam tip — memory hook

AD join equals catalog plus admin. Everything else is noise.

Want the full bank of 425 questions for Implementing and Configuring Cisco Identity Services Engine (SISE 300-715)? See all practice exams.