300-208 Sample Questions

300-208 Sample Questions & Answers

Identity management and device administration tie for the heaviest weight, both for daily operation and for architecture design, with smaller portions on TrustSec, designing secure wireless access with ISE, and troubleshooting identity deployments.

Launch the full 300-208 simulator →

Showing 8 of 17 free samples.

  1. Question 1Intermediate

    In the command 'aaa authentication default group tacacs local', how is the word 'default' defined? A.Command setB.Group nameC.Method listD.Login type

    Show answer & explanation

    Correct answer: C

  2. Question 2Intermediate

    Changes were made to the ISE server while troubleshooting, and now all wireless certificate authentications are failing. Logs indicate an EAP failure. What is the most likely cause of the problem? A.EAP-TLS is not checked in the Allowed Protocols listB.Certificate authentication profile is not configured in the Identity StoreC.MS-CHAPv2-is not checked in the Allowed Protocols listD.Default rule denies all trafficE.Client root certificate is not included in the Certificate Store

    Show answer & explanation

    Correct answer: A

  3. Question 3Intermediate

    The NAC Agent uses which port and protocol to send discovery packets to an ISE Policy Service Node? A.tcp/8905B.udp/8905C.http/80D.https/443

    Show answer & explanation

    Correct answer: B

  4. Question 4IntermediateSelect 2

    Which two conditions are valid when configuring ISE for posturing? (Choose two.) A.DictionaryB.member OfC.Profile statusD.FileE.Service

    Show answer & explanation

    Correct answers: D, E

  5. Question 5IntermediateSelect 3

    Refer to the exhibit.Which three statements about the given configuration are true? (Choose three.) A.TACACS+ authentication configuration is complete.B.TACACS+ authentication configuration is incomplete.C.TACACS+ server hosts are configured correctly.D.TACACS+ server hosts are misconfigured.E.The TACACS+ server key is encrypted.F.The TACACS+ server key is unencrypted.

    300-208 sample question 5
    Show answer & explanation

    Correct answers: B, C, F

  6. Question 6Intermediate

    In AAA, what function does authentication perform? A.It identifies the actions that the user can perform on the device.B.It identifies the user who is trying to access a device.C.It identifies the actions that a user has previously taken.D.It identifies what the user can access.

    Show answer & explanation

    Correct answer: B

  7. Question 7Intermediate

    Identity Management/Secure Access · Implement wired/wireless 802.1X

    A network security administrator is configuring 802.1X phasing on a Cisco Catalyst switch. The goal is to allow all traffic from endpoints while logging authentication failures to Cisco ISE to analyze the readiness of the environment without disrupting user access. Which configuration mode achieves this objective?

    Show answer & explanation

    Correct answer: C

    Monitor Mode, achieved by the configuration command 'authentication open' on the switch port, allows traffic to pass even if authentication fails. This enables administrators to see which devices would fail authentication in a Closed Mode scenario without actually blocking their access, making it the ideal first phase for deployment.

  8. Question 8Advanced

    Identity Management/Secure Access · Implement device administration

    An engineer is defining a TACACS+ Command Set in Cisco ISE for a group of junior administrators. They must be allowed to view interface statistics but strictly prohibited from changing any interface configuration. Which command definition strategy best satisfies this requirement?

    Show answer & explanation

    Correct answer: B

    The most secure and efficient method is to permit specifically 'show *' (or 'show interface *' if more granularity is needed) and rely on the default behavior of the Command Set to deny everything else. Explicitly denying 'interface *' is risky if the default is Permit, and unnecessary if the default is Deny.

Ready for the real thing?

The full 300-208 simulator has every exam-style question, timed mode, and instant scoring.