[Free] 2017(Oct) EnsurePass Braindumps Cisco 500-254 Dumps with VCE and PDF 1-10

EnsurePass
2017 Oct Cisco Official New Released 500-254
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/500-254.html

Implementing and Configuring Cisco Identity Services Engine (SISE)

Question No: 1

Which two elements must you configure on a Cisco Wireless LAN Controller to allow Cisco ISE to authenticate wireless users? (Choose two.)

  1. Configure Cisco ISE as a RADIUS authentication server and enter a shared secret.

  2. Configure Cisco ISE as a RADIUS accounting server and enter a shared secret.

  3. Configure all attached LWAPs to use the configured Cisco ISE node.

  4. Configure RADIUS attributes for each SSID.

  5. Configure each WLAN to use the configured Cisco ISE node.

  6. Configure the Cisco Wireless LAN Controller to join a Microsoft Active Directory domain.

Answer: A,E

Question No: 2

Which three Cisco TrustSec enforcement modes are used to help protect network operations when securing the network? (Choose three.)

  1. logging mode

  2. monitor mode

  3. semi-passive mode

  4. low-impact mode

  5. closed mode

Answer: B,D,E

Question No: 3

Which statement is correct about Change of Authorization?

  1. Change of Authorization is a fundamental component of Cisco TrustSec and Cisco ISE.

  2. Change of Authorization can be triggered dynamically based on a matched condition in a policy, and manually by being invoked by an administrator operation.

  3. It is possible to trigger Change of Authorization manually from the ISE interface.

  4. Authentication is the supported Change of Authorization action type.

Answer: D

Question No: 4

The default Cisco ISE node configuration has which role or roles enabled by default?

  1. Administration only

  2. Inline Posture only

  3. Administration and Policy Service

  4. Policy Service, Monitoring, and Administration

Answer: D

Question No: 5

Inline Posture nodes support which enforcement mechanisms?

  1. VLAN assignment

  2. downloadable ACLs

  3. security group access

  4. dynamic ACLs

Answer: B

Question No: 6

What is the process for Cisco ISE to obtain a signed certificate from a CA?

  1. Request a certificate from the CA, and import the CA-signed certificate into ISE.

  2. Generate a CSR; download the certificate from the CA; bind the CA-signed certificate with its private key, and import the CA-signed certificate into ISE.

  3. Generate a CSR; export the CSR to the local file system and send to the CA; download the certificate from the CA, and bind the CA-signed certificate with its private key.

  4. Submit a CSR to the CA; download the certificate from the CA; bind the CA-signed certificate with its private key, and import the CA-signed certificate into ISE.

Answer: C

Question No: 7

What is the Cisco ISE default admin login name and password?

  1. admin/admin

  2. admin/cisco

  3. ISEAdmin/admin

  4. admin/no default password-the admin password is configured at setup

Answer: D

Question No: 8

What are two methods to verify that Cisco ISE is properly connected to AD? (Choose two.)

  1. Use the Test Connection feature in the Cisco ISE External Identity Sources Active Directory.

  2. View the Active Directory Log /opt/CSCOcmp/logs/ad_agent.log.

  3. Use the ISE Dashboard Summary alarms.

  4. Use ktpass to determine if the Kerberos ticket is valid.

Answer: A,B

Question No: 9

Where is the license installed within Cisco ISE deployment?

  1. A license is installed on the Policy Service node within ISE deployment.

  2. A license is installed on the primary or secondary Administration node within ISE deployment.

  3. A license is installed only on the primary Administration node within ISE deployment.

  4. A license is preinstalled for ISE deployment.

Answer: C

Question No: 10

Which of these is NOT a high-availability option that is available for Cisco ISE deployments?

  1. In the event of failure of the Primary Administration node, the standby instance automatically becomes active.

  2. In the event of failure of the Primary Monitoring node, the standby instance automatically becomes active.

  3. Clustering of Policy Service nodes to provide N 1 redundancy

  4. Stateless failover of Inline Posture nodes

Answer: A

100% Free Download!
Download Free Demo:500-254 Demo PDF
100% Pass Guaranteed!
Download 2017 EnsurePass 500-254 Full Exam PDF and VCE

EnsurePass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 EnsurePass IT Certification PDF and VCE

You must be logged in to post a comment.

Proudly powered by WordPress   Premium Style Theme by www.gopiplus.com