A network engineer is configuring a network device that needs to filter traffic based on security group tags using a security policy on a routed interface.Which command should be used to accomplish this task?
Question 12
In a Cisco ISE split deployment model, which load is split between the nodes?
Question 13
What is the deployment mode when two Cisco ISE nodes are configured in an environment?
Question 14
An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened.From which Cisco ISE persona should this traffic be originating?
Question 15
What does a fully distributed Cisco ISE deployment include?
Question 16
An engineer is configuring 802.1X and wants it to be transparent from the users' point of view. The implementation should provide open authentication on the switch ports while providing strong levels of security for non-authenticated devices.Which deployment mode should be used to achieve this?
Question 17
A network administrator changed a Cisco ISE deployment from pilot to production and noticed that the JVM memory utilization increased significantly. The administrator suspects this is due to replication between the nodes.What must be configured to minimize performance degradation?
Question 18
An administrator is attempting to replace the built-in self-signed certificates on a Cisco ISE appliance. The CA is requesting some information about the appliance in order to sign the new certificate.What must be done in order to provide the CA this information?
Question 19
An administrator is adding network devices for a new medical building into Cisco ISE. These devices must be in a network device group that is identifying them as`Medical Switch` so that the policies can be made separately for the endpoints connecting through them.Which configuration item must be changed in the network device within Cisco ISE to accomplish this goal?
Question 20
An organization wants to split their Cisco ISE deployment to separate the device administration functionalities from the main deployment. For this to work, the administrator must deregister any nodes that will become a part of the new deployment, but the button for this option is grayed out.Which configuration is causing this behavior?