exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 47 discussion

Actual exam question from Cisco's 300-715
Question #: 47
Topic #: 1
[All 300-715 Questions]

An organization wants to standardize the 802.1X configuration on their switches and remove static ACLs on the switch ports while allowing Cisco ISE to communicate to the switch what access to provide.
What must be configured to accomplish this task?

  • A. dynamic access list within the authorization profile
  • B. extended access-list on the switch for the client
  • C. security group tag within the authorization policy
  • D. port security on the switch based on the client's information
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IlPerdan0
Highly Voted 1 year, 10 months ago
Selected Answer: A
A is more reasonable, as the question did not mention about SGL/TrustSec
upvoted 5 times
...
NullNull88
Most Recent 7 months, 4 weeks ago
It says they want to "remove static ACLs" and it does not mention wanting Tagging/SGT
upvoted 1 times
...
sajoz123
11 months, 1 week ago
It states "Dynamic ACL". https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure-per-user-dynamic-access-contro.html
upvoted 1 times
...
webwalker00
1 year, 1 month ago
Selected Answer: A
A because is specifically mentions ACL's. SGT is a different mechanism for access control.
upvoted 2 times
...
Githinji
1 year, 3 months ago
The answer is A. https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-11/config-guide/b_wl_17_eleven_cg/m_dACL.pdf ACLs to a connected Cisco ISE server and download them to the controller when a wireless client joins. Such ACLs are referred to as downloadable ACLs, per-user Dynamic ACLs, or dACLs
upvoted 1 times
...
THEODORABLE
1 year, 5 months ago
Selected Answer: C
C is the correct answer--I am going against the mainstream here... Don't confuse Dynamic ACL with Downloadable ACL (DACL) (see https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html). ISE doesn't dictate dynamic ACLs, I think the question is hinting at SGACL where ISE pushes the Egress policy (matrix) to all trustsec clients along with the CTS environment data. therfore ISE is instructing the switch for access control, and BTW Trustsec is intended to replace static ACLE within the enterprise infrastructure (see comment below).
upvoted 2 times
NikoTomas
8 months ago
Correct is A - DACL. --- SGACL does NOT override Port ACL for sure. Port ACL is overriden only by dACL (downloadable or dynamic – they are sometimes used in the same meaning) Real case: “We are moving from traditional DACL to SGACL and we've noticed that the existing static ACL applied to the port that enforces the traffic when the device has not authenticated yet into the network, overrides the SGACL downloaded from ISE. With DACL this does not happen and the DACL has higher priority over the port ACL, but for some reason this is not the case for SGACLs.” Advised solution: “To retain your Port ACL and use SGT/SGACL you'd probably have to have an ISE authz policy that assigns an SGT as well as a "permit any" DACL to negate the Port ACL.” https://community.cisco.com/t5/network-access-control/port-acl-overrides-sgacl/td-p/4621584
upvoted 1 times
...
...
tururu1496
1 year, 11 months ago
Selected Answer: A
A is correct. It replaces static ACL with dynamic ACL and not introduce the whole new technology
upvoted 3 times
...
[Removed]
2 years ago
The answer is A based on the explanation below, SGTs are not for replacing static acls, they have their own purpose with Trustsec
upvoted 3 times
...
[Removed]
2 years ago
Selected Answer: A
SGTs are usable where Trust Sec is deployed, the question simply asks about a better way of handling ACLs, substitute for Static ACLs should be Dynamic ACLs configured on ISE Authorisation Profiles. https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure-per-user-dynamic-access-contro.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago