Font size
S
M
L
XL
WorksheetsCCNP-Sec-SISAS-Pre-Assessment
Total questions: 10
Worksheet time: 10mins
Name
Class
Date
1.
Which of the following best describes an AV-pair?
a)
When communicating with an AAA protocol, the AV-pair stipulates a common attribute or object and its assigned value
b)
Cisco likes to throw in terms to confuse the reader
c)
The AV-pair is used to choose either TACACS+ or RADIUS
d)
The AV-pair is used to specify the quality of service (QoS) for audio and video traffic.
2.
What are the two primary reasons for using external identity stores
a)
Performance
b)
Monitoring
c)
Scalability
d)
Management
3.
What are the three main components of IEEE 802.1X
a)
Agent, broker, authentication server
b)
Supplicant, authorizer, authorization server
c)
Authentication server, supplicant, authenticator
d)
EAP, RADIUS, TLS
4.
What is one of the main reasons that MAB is used in modern-day networks
a)
Most endpoints, such as printers and IP phones, do not have supplicants and therefore cannot use 802.1X
b)
The endpoints can have a supplicant, but the enablement and configuration of that supplicant could be overcomplicated or operationally difficult for the company. Therefore, the company opts to use MAB instead
c)
The endpoints mostly do have supplicants, but those are not compatible with Cisco networks
d)
MAB is equally as secure as 802.1X and therefore is chosen often to save the company the operational difficulties of configuring the supplicants on such disparate endpoints.
5.
A mobile device manager is which of the following
a)
A network administrator responsible for onboarding all mobile devices into the authentication server
b)
An application that runs on a mobile device, allowing the user or endpoint to manage the authentication server and other network devices
c)
A wireless access point that detects rogue mobile endpoints
d)
A software system or service that provides advanced posture assessment for mobile endpoints
6.
In a single-node/standalone deployment of ISE which of the following is true
a)
Each ISE appliance services a single network access device
b)
Each ISE appliance services only a single ISE persona
c)
All endpoints bypass authentication
d)
All core ISE personas reside on a single ISE appliance
7.
Profiling policies within ISE can leverage all of the following protocols to determine the type of endpoint that is accessing the network EXCEPT which? (Select two.)
a)
DHCP
b)
RADIUS
c)
SSH
d)
HTTPS
e)
FTP
8.
What is the purpose of a certificate authentication profile (CAP)?
a)
Defines which CA to use for revocation checking via either certificate revocation lists (CRLs) or online certificate status protocol (OCSP).
b)
Used with MSCHAPv2 for a client to validate the authentication server
c)
Serves as the identity source for certificate authentications and defines the field of a certificate whose data will be extracted and used as the principle identity for the authorization process.
d)
Serves as the identity source for certificate authentications and defines the field of a certificate whose data will be extracted and used as the principle identity for the authorization process.
9.
What is the purpose of the continue option of an authentication rule?
a)
The continue option is used to send an authentication down the list of rules in an authentication policy until there is a match
b)
The continue option sends an authentication to the next sub-rule within the same authentication rule
c)
The continue option is used to send an authentication to the authorization policy, even if the authentication was not successful
d)
The continue option will send an authentication to the selected identity store.
10.
What is unique about Cisco’s downloadable Access Control Lists (dACLs)?
a)
Cisco dACLs allow the RADIUS server to apply ACLs that exist on the switch simply by sending the name of the ACL in the RADIUS AV pairs, while non-Cisco network devices cannot apply ACLs
b)
Cisco downloadable ACLs are created by experts at Cisco and published to Cisco.com where Cisco ISE can download the ACLs
c)
Cisco dACLs are created entirely on the RADIUS server, and the full ACL is sent down to the network device within RADIUS AV pairs, while non-Cisco network devices must create the ACL on the individual local network device
d)
Cisco dACLs are unique because they are downloaded from ISE and applied to the Cisco ASA that is in the network path, relieving the network device from the burden of traffic control.
Reset
