exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 38 discussion

Actual exam question from Cisco's 300-715
Question #: 38
Topic #: 1
[All 300-715 Questions]

Which two actions occur when a Cisco ISE server device administrator logs in to a device? (Choose two.)

  • A. The Cisco ISE server queries the internal identity store.
  • B. The device queries the external identity store.
  • C. The device queries the Cisco ISE authorization server.
  • D. The device queries the internal identity store.
  • E. The Cisco ISE server queries the external identity store.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tliz
Highly Voted 1 year, 9 months ago
Selected Answer: AE
The answer is A & E. It is not C, because the question uses the words 'logs in' and option C uses the term authorization. Logging in is Authentication, not Authorization
upvoted 8 times
NikoTomas
8 months, 4 weeks ago
I think that A & E are correct. “The device administrator performs the task of setting up a device to communicate with the Cisco ISE server. When a device administrator logs on to a device, the device queries the Cisco ISE server (NOTE: queries ISE server, NOT INTERNAL OR EXTERNAL IDENTITY STORE), which in turn queries an INTERNAL or EXTERNAL IDENTITY STORE, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes.” https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html
upvoted 1 times
...
...
vsu56986
Highly Voted 3 years, 3 months ago
Could be A,C and E. The device queries ISE and ISE can use an internal or external identity store. https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A The device administrator performs the task of setting up a device to communicate with the Cisco ISE server. When a device administrator logs on to a device, the device queries the Cisco ISE server, which in turn queries an internal or external identity store, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes.
upvoted 5 times
NikoTomas
8 months, 4 weeks ago
Correct are A, E. C is incorrect, because question is about authentication, not authorization (it comes later).
upvoted 2 times
...
...
Euser
Most Recent 7 months, 3 weeks ago
The answer is A&E. It the authentication server's(ISE) role.
upvoted 2 times
...
NullNull88
8 months, 2 weeks ago
A "Device" never ever queries an identity store directly. That eliminates two of them. ISE is the only thing that queries an ID Store and in this case, Device Access is only internal database. This IS About TACACS because it is talking about Device Administrators. With those things in mind it becomes easier to pick which ones are viable options. Take a quick look at the vendor docs which echo this.
upvoted 2 times
...
XBfoundX
1 year, 1 month ago
For me answer is C and E https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html#:~:text=The%20device%20administrator%20performs%20the,details%20of%20the%20device%20administrator. the admin log into the switch and after that the switch have radius or tacacs, after that you have configured a policy in ISE, usually for network access what you do is connecting an AD to ISE so that Cisco ISE can query an external identity and validate the user that the admin is actually using for authetication
upvoted 1 times
XBfoundX
1 year, 1 month ago
ok.... this question is really tricky and cringe... after reading that C is talking about authorization... so.... because this is an authentication session i think that Cisco is thinking about what ISE can do when a user logs into a device? The device of course has tacacs or radius or both configured, and what ISE can do is or looking for an internal or an external identity store so A and E at the end....
upvoted 1 times
...
...
THEODORABLE
1 year, 6 months ago
Selected Answer: AE
Im going with A& E. there is an internal ISE admin database and it can use external Identity source such as AD. but the key in the question is asking about an ISE admin logging into ISE- not sure what they mean by "device"; if they are talking NAD then it would be Tacacs+
upvoted 2 times
...
aHash
2 years ago
Typical tricky question. A,C,E all stand correct but authorization comes only after successful authentication so I would choose A, E as the correct answers.
upvoted 2 times
...
liqucika
2 years, 6 months ago
Selected Answer: AE
Can be internal or external
upvoted 2 times
...
Seawanderer
2 years, 6 months ago
Selected Answer: AE
"Cisco ISE server device administrator" makes me think it's an ISE admin. An ISE admin can have internal or external credentials.
upvoted 2 times
user_topic
2 years, 4 months ago
Bro, this question doesn't make any sense at all.
upvoted 2 times
...
...
minniengan
2 years, 7 months ago
Selected Answer: AC
Does "Cisco ISE server device administrator" mean internal identity store?
upvoted 1 times
...
Kareemali
3 years, 3 months ago
For Sure A & E are the strongest answers
upvoted 1 times
...
japm1801
3 years, 6 months ago
y our case, to achieve a device login with ISE, we use internal user DB, so the answers should be A & C, the device queries the ISE and the ISE queries the internal database
upvoted 2 times
...
MrCalifornia
3 years, 7 months ago
CORRECT IS C & E READ THE MANUALS When a device administrator logs on to a device, the device queries the Cisco ISE server, which in turn queries an internal or external identity store, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes. https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html
upvoted 2 times
YmerG
1 year, 9 months ago
So A, C and E according to your answer.
upvoted 1 times
...
...
Pipi
3 years, 7 months ago
Correct answer is A and E. https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A
upvoted 3 times
...
kraditheo
3 years, 9 months ago
I think the correct answers are A and E https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...