exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 197 discussion

Actual exam question from Cisco's 300-715
Question #: 197
Topic #: 1
[All 300-715 Questions]

A network engineer needs to deploy 802.1x using Cisco ISE in a wired network environment where thin clients download their system image upon bootup using PXE. For which mode must the switch ports be configured?

  • A. closed
  • B. restricted
  • C. monitor
  • D. low-impact
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cachaman
1 month, 1 week ago
Selected Answer: D
C and D are correct. Monitor mode will work fine. Low-Impact mode will wor as well, as long as you allow DHCP, DNS, and TFTP (including all UDP to FTP servers) https://community.cisco.com/t5/network-access-control/pc-imaging-on-nac-secured-ports/td-p/3486098
upvoted 1 times
...
factmrojas
9 months, 2 weeks ago
Selected Answer: D
Low-impact mode allows necessary network operations (such as PXE booting) before full 802.1X authentication, providing the right balance of initial access and security enforcement. This mode is ideal for environments with thin clients that need to download their system image upon bootup.
upvoted 1 times
...
XBfoundX
1 year, 5 months ago
Low impact mode: Unless you have a strict compliance/requirement for Closed Mode, I would suggest you consider using Low Impact Mode with a restrictive pre-auth ACL that permits basic protocols like DHCP, DNS, TFTP and denies everything else. The vast majority of customers that I've worked with feel that LIM provides the necessary balance of security vs. user experience. https://community.cisco.com/t5/network-access-control/device-sensor-without-dhcp-snooping/td-p/4303940
upvoted 2 times
...
flambadone
1 year, 7 months ago
Selected Answer: D
I agree with low impact mode - Low impact mode allows stuff to flow before a final auth. Could be update servers (SCCM, Win Update, etc) or thin client PXE stuff. Have done this in prod in the past.
upvoted 1 times
...
redpassion
1 year, 11 months ago
Selected Answer: D
low impact mode.
upvoted 2 times
...
rhylos
1 year, 11 months ago
Selected Answer: C
C - Monitor mode .They key word is MUST. in Low Impact mode, MIGHT not be able to get all the traffic. DHCP , DNS and EAP by default. Not sure what ports will be used when connect using PXE to DL images. Monitr mode will always work.
upvoted 1 times
...
Cnoteone
2 years, 1 month ago
Selected Answer: D
Low-Impact Mode–This mode builds on the monitor mode. With open access in place, IP ACLs are used to control pre-authentication and post-authentication network access. A Pre-Auth ACL on the switch port controls network access before an endpoint can successfully authenticate. A named or downloadable ACL that is received from ISE grants specific level of access upon successful authentication. The Low-Impact mode is ideal for a Preboot Execution Environment (PXE) boot environments where thin clients have to download the operating system from the network before attempting network authentication. Since devices get IP address immediately after they connect to the network, and authentication may take place in parallel or later, we recommend that you do not make VLAN changes in the Low-Impact mode.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago