300-715 — Frequently Asked Questions
Community-vetted answers to 16 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
Cisco ISE Guest Portal Types for Wireless Access
Self-Registered portals allow guests to create their own accounts via email verification, violating the requirement that guests cannot create accounts.
No, Hotspot Guest Access typically relies on Acceptable Use Policy (AUP) acceptance without requiring specific user credentials.
Which WLC Profiling Mechanism Sends Device Data to Cisco ISE?
SNMP is an ISE-side probe that queries the WLC for attributes; it is not a Device Sensor protocol configured on the WLC to push client data to ISE.
It forwards DHCP and RADIUS attributes such as hostname, device type, and OS so ISE can build endpoint profiles for authorization policies.
Uploading Compliance Module for Cisco ISE Posture Agent
The portal is only the navigation path; the actual upload happens when you select agent resources from the local disk inside the Client Provisioning Resources page.
Yes, go to Policy > Results > Client Provisioning > Resources, click Add, and choose Agent resources from local disk to upload the downloaded compliance module.
ISE TACACS+ Profile for Full ASA Admin Access Without Enable?
ISE returns the Default Privilege in the TACACS+ authorization reply; a value of 1 puts the admin in user exec, forcing the enable command that the requirement explicitly forbids.
Enumerating all commands is impractical and error-prone; selecting "Permit any command that is not listed below" grants full access while still allowing explicit denies.
Which Sponsor Group Restricts Guest Account Management to Same-Group Sponsors?
OWN_ACCOUNTS limits a sponsor to the guest accounts that sponsor personally created, so peers in the same business unit would be invisible — narrower than the stated requirement.
GROUP_ACCOUNTS lets a sponsor manage only accounts created by sponsors in its own sponsor group, while ALL_ACCOUNTS grants management of every guest account across the deployment.
Which ISE Persona Makes Authorization Decisions from Threat and Vulnerability Attributes?
pxGrid only carries attributes between ISE and the external adapters; the authorization decision itself is evaluated by the Policy Service (PSN) persona, which is what the question asks for.
Adapter integration does use the pxGrid framework, but the question asks which persona makes the authorization decision, and that is always Policy Service.
Which Authorization Profile Option Supports MSE Room-Based Wireless Access?
MAP Location is evaluated as a condition in the authorization policy rule using data from the MSE integration. It cannot be selected inside the Authorization Profile, which is what this question asks about.
ISE queries the integrated MSE for the endpoint's location about every five minutes and triggers a CoA when the location changes, re-applying the room-scoped authorization profile.
Which Two ISE Actions Enable WLC Monitor Access?
The WLC authorizes by management role, so ISE must return the Monitor role in the TACACS profile to restrict helpdesk users to the Monitor tab.
AireOS controllers use role-based access control over whole UI menus rather than per-command authorization, so command sets (E) have no effect.
← Back to 300-715 Designing Cisco Network Infrastructure Study Guide