Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SISE

Total questions: 25

Worksheet time: 9mins

Name
Class
Date
1.

Which of the following is NOT an ISE feature?

a)

Guest Management

b)

Profiler

c)

Centralized Policy Administration

d)

URL Filtering

2.

Which of the following is NOT a mandatory ISE persona?

a)

PxGrid

b)

PAN

c)

MnT

d)

PSN

3.

Which ISE deployment mode is defined with "authentication open" command?

a)

Monitor Mode

b)

Low Impact Mode

c)

Closed Mode

d)

Open Auth Mode

4.

What is the meaning of DROP option in Authentication Policy?

a)

Drop an e-Mail to the ISE Admin

b)

Take a Drop-Down approach

c)

Drop the Access_Request from NAD

d)

Reply with Access_Reject to NAD

5.

In Cisco TrustSec, SGACLs are written based on _______

a)

MAC addresses of the Endpoints

b)

Layer 3 information only

c)

Layer 4 information only

d)

Layer 3 and Layer 4 information

6.

What does a NAD do after receiving a RADIUS CoA Message?

a)

Sends EAP Success message

b)

Re-authenticats the session

c)

Open the port

d)

Close the port

7.

In HOTSPOT Guest access, when is the user considered to be authenticated as guest?

a)

After 802.1x times out

b)

After MAB times out

c)

After accepting the AUP

d)

After logging in to the Guest Portal

8.

Which of the following is NOT performed during BYOD onboarding of a device?

a)

Device Registration

b)

Supplicant Provisioning

c)

Certificate Provisioning

d)

AV installation checks

9.

Employees use this portal to manage their BYOD devices.

a)

Sponsor Portal

b)

My Devices Portal

c)

BYOD Portal

d)

Guest Portal

10.

Which of the following is NOT a valid value for Session:PostureStatus attribute?

a)

QUARANTINE

b)

COMPLIANT

c)

NON-COMPLIANT

d)

UNKNOWN

11.

Why TACACS+ is better suited for Device Administration than RADIUS?

a)

Encrypts the entire payload

b)

Runs over TCP/49

c)

Separates Authentication and Authorization

d)

Cisco Propitiatory

12.

Which ISE persona runs Device Admin Service?

a)

PAN

b)

MnT

c)

PSN

d)

PxGrid

13.

Which attribute/value pair tells ISE that the user is connected via a Wireless Network?

a)

Service_Type = Wireless_802.11

b)

Service_Type = WiFi

c)

NAS_Port_Type = Ethernet

d)

NAS_Port_Type = Wireless_802.11

14.

In Cisco TrustSec, where SGACLs are enforced?

a)

On the ingress switches

b)

On the egress switches

c)

On the core switch

d)

On the ISE

15.

What does Cisco ISE do if a device is marked as 'lost' in the My Devices Portal?

a)

Moves the MAC address of the device to the Blacklist Endpoint Group

b)

Deletes the MAC address from the Internal Endpoint Database

c)

Revokes the device's certificate

d)

Registers a police compliant

16.

An endpoint does not have 802.1X supplicant running on it. How will this endpoint authenticate to ISE and get access to network resources?

a)

Using NAC Agent

b)

Using Discovery Agent

c)

Using MAB (MAC Authentication Bypass)

d)

This device cannot get network access

17.

Which of the following ISE modules detects the presence of virus/malware in an endpoint?

a)

ISE NAC Agent Module

b)

ISE Profiler Module

c)

ISE Posture (Endpoint Compliance Services) Module

d)

None of the above

18.

Identity Source Sequence (ISS) means . . .

a)

Authenticating using AD only

b)

Authenticate device first, then authenticate the user next

c)

Authenticate the user using Internal User Identity Store only

d)

Check multiple databases in sequence to authenticate the user

19.

During MAB, _________ is used as the username and password in the RADIUS ACCESS-REQUEST message.

a)

Username/Password provided by the user

b)

UUID of the endpoint

c)

IP Address of the endpoint

d)

MAC Address of the endpoint

20.

Which of the following policies allow you to define which software packages/agents will be pushed to the endpoint, based on its OS, user-group or other conditions?

a)

Client Provisioning Policy

b)

Posture Policy

c)

Profiler Policy

d)

NAC Agent Policy

21.

After the user is authenticated, all user traffic must pass through ISE PSN for inspection.

a)
True
b)
False
22.

In TACACS+ Command Sets, which of the following grants overrides any other grant?

a)

PERMIT

b)

DENY

c)

DENY_ALWAYS

d)

FORBIDDEN

23.

Which of the following is NOT true in regards to Cisco ISE 3.X Licensing?

a)

Needs Smart Licensing

b)

License tiers are stacked

c)

Essentials licenses are perpetual

d)

Advantage Tier also includes functions of Essential Tier

24.

In Central Web Authentication, Redirect_ACL is configured on the switch and referenced in the Authorization Profile.

a)
True
b)
False
25.

Select all the protocols used by Cisco IOS Device Sensor feature to gather raw endpoint data from the devices. [Choose 3 answers]

a)

HTTP/HTTPS

b)

CDP

c)

LLDP

d)

DHCP Snooping