Refer to Following: aaa new model tacacs-server host single connection tacas-server key cisco123 Which statement about the authentication protocol used in the configuration is true?
A. Authentication request contains username, encrypted password, NAS IP address, and port.
B. Authentication and authorization requests are sent in a single open connection between the network device and the TACACS+ server

C. Authentication request contains username, password, NAS IP address and port.
D. Authentication and authorization request packets are grouped together in a single packet.
300-208 exam Correct Answer: B
Which two Active Directory authentication methods are supported by Cisco ISE? (Choose two.)
Correct Answer: AB
How frequently does the Profiled Endpoints dashlet refresh data?
A. every 30 seconds
B. every 60 seconds
C. every 2 minutes
D. every 5 minutes
300-208 dumps Correct Answer: B
Which protocol sends authentication and accounting in different requests?
C. EAP-Chaining
Correct Answer: B
Which statement about system time and NTP server configuration with Cisco ISE is true?
A. The system time and NTP server settings can be configured centrally on the Cisco ISE.

B. The system time can be configured centrally on the Cisco ISE, but NTP server settings must be configured individually on each ISE node.
C. NTP server settings can be configured centrally on the Cisco ISE, but the system time must be configured individually on each ISE node.
D. The system time and NTP server settings must be configured individually on each ISE node.
300-208 pdf Correct Answer: D
Which technology performs CoA support Posture Service?
A. External root CA
B. Cisco ACS
C. Cisco ISE
D. Internal root CA
Correct Answer: C
Which three components comprise the Cisco ISE profiler? (Choose three.)
A. the sensor, which contains one or more probes
B. the probe manager
C. a monitoring tool that connects to the Cisco ISE
D. the trigger, which activates ACLs
E. an analyzer, which uses configured policies to evaluate endpoints
F. a remitter tool, which fails over to redundant profilers
300-208 vce Correct Answer: ABE
Which three algorithms should be avoided due to security concerns? (Choose three.)
A. DES for encryption
B. SHA-1 for hashing
C. 1024-bit RSA
D. AES GCM mode for encryption
F. 256-bit Elliptic Curve Diffie-Hellman

G. 2048-bit Diffie-Hellman
Correct Answer: ABC
Which feature must you configure on a switch to allow it to redirect wired endpoints to Cisco ISE?
A. the http secure-server command
B. RADIUS Attribute 29
C. the RADIUS VSA for accounting
300-208 exam Correct Answer: A
Refer to the exhibit.
300-208 dumps
You are troubleshooting RADIUS issues on the network and the debug radius command returns the given output. What is the most likely reason for the failure?
A. An invalid username or password was entered.
B. The RADIUS port is incorrect.
C. The NAD is untrusted by the RADIUS server.
D. The RADIUS server is unreachable.
E. RADIUS shared secret does not match
Correct Answer: A
Which two posture redirect ACLs and remediation DACLs must be pushed from Cisco ISE to a Cisco IOS switch if the endpoint must remediate itself? The ISE IP address is and the IP address of the remediating server is (Choose two.)
A. ip access-l ex ACL-POSTURE-REDIRECT deny udp any any eq domain deny ip any host permit tcp any any eq 80 permit tcp any any eq 443
B. ip access-l ex ACL-POSTURE-REDIRECT deny udp any any eq domain deny ip any host deny ip any host permit tcp any any eq 80permit tcp any any eq 443
C. ip access-l ex ACL-POSTURE-REDIRECT deny udp any any eq domain permit ip any host permit ip any host deny ip any any
D. POSTURE_REMEDIATION DACL permit udp any any eq domain permit tcp any host permit tcp any any eq 80 permit tcp any any eq 443
E. POSTURE_REMEDIATION DACL permit udp any any eq domain deny tcp any host permit tcp any any eq 80 permit tcp any any eq 443 permit ip any host
F. POSTURE_REMEDIATION DACL permit udp any any eq domain deny tcp any host deny ip any host permit tcp any any eq 80 permit tcp any any eq 443
300-208 dumps Correct Answer: BD
When you add a new PSN for guest access services, which two options must be enabled under deployment settings?(Choose two.)
A. Admin
B. Monitoring
C. Policy Service
D. Session Services
E. Profiling
Correct Answer: CD
What are three ways that an SGT can be assigned to network traffic?
A. Manual binding of the IP address to an SGT
B. Manually configured on the switch port
C. Dynamically assigned by the network access device
D. Dynamically assigned by the 802.1X authorization result
E. Manually configured in the NAC agent profile
F. Dynamically assigned by the AnyConnect network access manager
300-208 pdf Correct Answer: ABD

300-208 dumps

