Cisco · Practice Exam · Professional · CCNP Security · Updated for 2026

Cisco 300-715 SISE Identity Services Engine Practice Exam

Cover the full 300-715 v1.1 blueprint — ISE architecture and deployment, policy enforcement, Web Auth and guest services, profiler, BYOD, endpoint compliance, and network access device administration — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
Version change ahead: The 300-715 exam is moving from v1.1 to v1.2. Per Cisco, the last day to test v1.1 is August 26, 2026 and the first day for v1.2 is August 27, 2026. This page reflects the current v1.1 blueprint. If you’re scheduling near or after that date, confirm which version you’ll sit and check Cisco’s exam topics for any v1.2 changes.
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

300-715 exam at a glance

Vendor
Cisco
Exam code
300-715 (SISE)
Full name
Implementing and Configuring Cisco Identity Services Engine
Product
Cisco Identity Services Engine (ISE)
Level
Professional
Blueprint
v1.1 (v1.2 begins August 27, 2026)
Duration
90 minutes
Role in CCNP
CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
Also earns
Cisco Certified Specialist – Security Identity Management Implementation
Domains
Seven, with published weights (see below); they sum to 100%
Prerequisites
None formally required; 802.1X, RADIUS/TACACS+, and switching/wireless knowledge is recommended
Delivery
Pearson VUE; test center or online proctored

Sources: Cisco — SISE (300-715) exam page · Cisco — official SISE v1.1 exam topics (PDF). Verify current details with Cisco before scheduling.

About the Cisco 300-715 SISE exam

The 300-715 SISE exam validates the skills to implement and configure Cisco Identity Services Engine (ISE) — the identity and access-control platform that delivers consistent, secure access across wired, wireless, and VPN networks. It covers ISE architecture and deployment, policy enforcement with 802.1X/MAB/TrustSec, Web Auth and guest services, profiling, BYOD onboarding, posture/endpoint compliance, and device administration. For how certification exams work generally, see the certification study guides in our Learning Hub.

SISE is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SISE being the identity/access option. Passing SISE on its own also earns the Cisco Certified Specialist – Security Identity Management Implementation credential. ISE identity underpins zero-trust access in SCAZT (300-740) and feeds identity to firewalls in SNCF (300-710).

Every PowerKram practice question maps to one of the seven weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.

300-715 exam domains and weights (v1.1)

Cisco publishes seven weighted domains for the 300-715 v1.1 exam, and they sum to 100%. Policy Enforcement is by far the heaviest at 25% — roughly a quarter of the exam — so make 802.1X, MAB, identity stores, TrustSec, and authorization policy your priority, then round out onboarding, profiling, and posture. Confirm the current weights on Cisco’s exam topics before scheduling.

Architecture and Deployment

Configure ISE personas (PAN, MnT, PSN, pxGrid); deployment options (standalone vs distributed); hardware and virtual-machine performance specs; and zero-touch provisioning.

10%
Policy Enforcement

Native AD and LDAP; identity stores (LDAP, AD, PKI, MFA, local, SAML IdP, REST ID); wireless and wired 802.1X (IBNS 2.0 monitor/low-impact/closed modes); MAB; Cisco TrustSec; and authentication/authorization policies and profiles. The single heaviest domain.

25%Heaviest domain
Web Auth and Guest Services

Configure web authentication; guest access services; and sponsor and guest portals for visitor onboarding.

15%
Profiler

Implement profiler services and probes; Change of Authorization (CoA); and endpoint identity management to classify and control devices dynamically.

15%
BYOD

Cisco BYOD functionality (use cases, components, flow); device onboarding using the internal CA with Cisco switches and wireless LAN controllers; certificates for BYOD; and block/allow lists.

15%
Endpoint Compliance

Posture services and client provisioning; posture conditions and policy; the compliance module; posture agents and operational modes; and the supplicant/authenticator/server model.

10%
Network Access Device Administration

Compare AAA protocols (RADIUS vs TACACS+); and configure TACACS+ device administration and command authorization for network-device management.

10%

Source: Cisco — official SISE v1.1 (300-715) exam topics (PDF). Weights are Cisco’s and sum to 100%. Note a v1.2 update begins August 27, 2026; verify the current edition before scheduling.

Who the 300-715 exam is for

SISE is aimed at engineers who build identity-based network access control:

  • Network and security engineers deploying Cisco ISE for wired, wireless, and VPN access control.
  • Identity and access specialists configuring 802.1X, MAB, TrustSec, and authorization policy.
  • NAC / endpoint teams running profiling, BYOD onboarding, and posture compliance.
  • CCNP Security candidates choosing the identity concentration alongside the SCOR 350-701 core.

Extend identity into zero-trust access with SCAZT (300-740), into firewall policy with SNCF (300-710), or pair it with email security in SESA (300-720). For where identity/access skills lead, see the cybersecurity career paths in our Career Hub.

What this 300-715 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for policy-enforcement questions where authentication vs authorization order matters.

Exam mode

Timed, full-length simulation spanning all seven domains at the real 90-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own SISE exam material, so you can verify each ISE configuration and policy choice against the source.

Score by weighted domain

Results break down across the seven weighted domains so you can see exactly which ISE area needs more work.

Sample 300-715 practice questions

Ten free questions across the 300-715 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.

Question 1 · Architecture and Deployment (10%)

Which ISE persona is responsible for all administration and configuration through the primary web GUI?

  1. The Policy Administration Node (PAN)
  2. The Monitoring node (MnT)
  3. The Policy Service Node (PSN)
  4. The pxGrid node
Show answer & explanation

Correct: A. The Policy Administration Node (PAN) provides the single administrative interface for configuration and policy management across the deployment. Understanding the four personas (PAN, MnT, PSN, pxGrid) is core to the architecture domain.

Why not the others: the MnT node (B) handles logging, monitoring, and reporting; the PSN (C) makes policy decisions and handles authentication/authorization; the pxGrid node (D) shares context with other platforms — none is the admin GUI.

Source: Cisco — SISE: architecture & personas → Further reading: PowerKram — SCAZT (300-740) →
Question 2 · Policy Enforcement (25%)

A device without an 802.1X supplicant (e.g. a printer) must still be granted controlled network access via ISE. Which method fits?

  1. Disabling authentication on the port
  2. MAC Authentication Bypass (MAB)
  3. Assigning a static public IP
  4. Turning off the switch
Show answer & explanation

Correct: B. MAC Authentication Bypass authenticates endpoints that can’t do 802.1X by using their MAC address as the identity, so ISE can still apply an authorization policy (often combined with profiling). It’s the standard fallback for headless devices.

Why not the others: disabling authentication (A) removes control entirely; a static public IP (C) is unrelated to access control; and turning off the switch (D) denies all access.

Source: Cisco — SISE: policy enforcement (MAB) → Further reading: PowerKram — SNCF (300-710) →
Question 3 · Policy Enforcement (25%)

Which Cisco technology uses Security Group Tags (SGTs) to enforce access based on role rather than IP address?

  1. Spanning Tree Protocol
  2. HSRP
  3. Cisco TrustSec
  4. NetFlow
Show answer & explanation

Correct: C. Cisco TrustSec assigns Security Group Tags to traffic based on identity/role and enforces policy with those tags (SGACLs), decoupling access control from IP addressing — a named policy-enforcement topic in ISE.

Why not the others: Spanning Tree (A) prevents switching loops, HSRP (B) provides gateway redundancy, and NetFlow (D) exports traffic telemetry — none enforce role-based access.

Source: Cisco — SISE: TrustSec →
Question 4 · Policy Enforcement (25%)

During phased 802.1X rollout, which IBNS 2.0 mode allows traffic even when authentication fails, so you can observe without blocking users?

  1. Closed mode
  2. Low-impact mode
  3. Monitor mode (open)
  4. Maintenance mode
Show answer & explanation

Correct: C. Monitor mode (open authentication) lets all traffic through while still logging authentication results, so administrators can validate policy before enforcing — the first step in a low-risk 802.1X deployment. Low-impact and closed modes progressively tighten enforcement.

Why not the others: closed mode (A) blocks all non-authenticated traffic; low-impact mode (B) permits limited traffic via a pre-auth ACL but still restricts; and “maintenance mode” (D) is not an IBNS deployment mode.

Source: Cisco — SISE: wired 802.1X & IBNS 2.0 →
Question 5 · Web Auth and Guest Services (15%)

Which ISE portal lets employees approve and create temporary guest accounts without administrator involvement?

  1. The sponsor portal
  2. The admin CLI
  3. The BIOS setup screen
  4. The switch console
Show answer & explanation

Correct: A. The sponsor portal lets authorized employees (sponsors) create and manage guest accounts, delegating visitor onboarding away from IT — a named guest-services capability alongside self-registration and hotspot portals.

Why not the others: the admin CLI (B), BIOS (C), and switch console (D) are not guest-sponsorship interfaces.

Source: Cisco — SISE: guest & sponsor portals →
Question 6 · Profiler (15%)

After ISE re-profiles a connected endpoint into a new group that changes its authorization, what mechanism applies the new access without the user reconnecting?

  1. A power cycle of the switch
  2. Change of Authorization (CoA)
  3. A DNS flush
  4. A new cable
Show answer & explanation

Correct: B. RADIUS Change of Authorization lets ISE push a new authorization (re-auth, VLAN/ACL change, or disconnect) to an active session — essential so profiling and posture results can dynamically adjust access in place.

Why not the others: a switch power cycle (A) and a new cable (D) disrupt the session rather than updating it gracefully, and a DNS flush (C) has nothing to do with authorization.

Source: Cisco — SISE: profiler & CoA →
Question 7 · BYOD (15%)

In native ISE BYOD onboarding, what does the internal Certificate Authority issue to each personal device?

  1. A dynamic public IP lease
  2. A physical smart card
  3. A one-time paper code only
  4. A unique client certificate for certificate-based authentication
Show answer & explanation

Correct: D. During BYOD onboarding, ISE’s internal CA issues a unique client certificate to the device so it can authenticate via EAP-TLS afterward — stronger and more manageable than shared passwords. Configuring the internal CA and BYOD certificates is an explicit objective.

Why not the others: a public IP lease (A) isn’t issued by a CA; a physical smart card (B) isn’t part of native onboarding; and a paper code alone (C) doesn’t provide certificate-based auth.

Source: Cisco — SISE: BYOD onboarding & certificates → Further reading: PowerKram — SCAZT (300-740) →
Question 8 · Endpoint Compliance (10%)

Which ISE capability checks whether a connecting device meets requirements (AV running, patches, disk encryption) before granting full access?

  1. A traceroute
  2. An SNMP walk
  3. Posture assessment
  4. A ping sweep
Show answer & explanation

Correct: C. Posture assessment evaluates endpoint health against posture conditions/policy (via an agent or agentless), then allows, quarantines, or remediates based on compliance — the core of the endpoint-compliance domain.

Why not the others: a traceroute (A), SNMP walk (B), and ping sweep (D) are diagnostics that don’t assess device compliance.

Source: Cisco — SISE: posture & compliance →
Question 9 · Network Access Device Administration (10%)

To control which CLI commands specific administrators can run on switches and routers, which AAA protocol does ISE use for device administration?

  1. SNMPv2c
  2. NTP
  3. ICMP
  4. TACACS+
Show answer & explanation

Correct: D. TACACS+ separates authentication, authorization, and accounting and supports per-command authorization, making it the protocol for device administration (privileged CLI control) — whereas RADIUS is typically used for network access. Comparing the two is an explicit objective.

Why not the others: SNMPv2c (A) is for monitoring/management data, NTP (B) syncs time, and ICMP (C) is for diagnostics — none provide command authorization.

Source: Cisco — SISE: device administration (TACACS+) → Further reading: PowerKram — SESA (300-720) →
Question 10 · Policy Enforcement (25%)

In an ISE authorization policy, what is ultimately returned to the network device to define what an authenticated user may access?

  1. A screensaver theme
  2. An authorization profile (e.g. VLAN, dACL, or SGT)
  3. A firmware image
  4. A DHCP lease time only
Show answer & explanation

Correct: B. The authorization profile is the result ISE returns — it bundles the permissions (VLAN assignment, downloadable ACL, Security Group Tag, and other attributes) the network device applies to the session. Authentication proves identity; the authorization profile defines access.

Why not the others: a screensaver theme (A), a firmware image (C), and a DHCP lease time (D) are not access-control results returned by an authorization policy.

Source: Cisco — SISE: authorization profiles →

Keep going: Learning & Career resources

SISE is the identity/access concentration in the CCNP Security track. Two PowerKram hubs back this exam.

Deep dive: Cisco ISE, the CCNP Security path, and study strategy

What Cisco ISE does

Cisco Identity Services Engine is the policy engine for network access: it authenticates users and devices (802.1X, MAB, certificates), profiles what they are, checks their posture, and returns an authorization result (VLAN, dACL, or SGT) that the switch, WLC, or VPN enforces. The exam mirrors that flow — identity store → authentication → profiling/posture → authorization → enforcement — which is why Policy Enforcement dominates the blueprint. See SCAZT (300-740) →

How SISE fits CCNP Security

CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SISE is the identity/access concentration; secure cloud access via SCAZT (300-740), firewalls via SNCF (300-710), and email via SESA (300-720) are related options. Passing SISE alone also earns Cisco Certified Specialist – Security Identity Management Implementation. See SNCF (300-710) →

Realistic study path and the v1.2 change

Policy Enforcement is a quarter of the exam, so build a lab: stand up ISE personas, wire 802.1X and MAB on a switch, configure identity stores and authorization profiles, then layer in profiling, BYOD with the internal CA, and posture. Because a v1.2 blueprint begins August 27, 2026, candidates testing near that date should confirm their version and check Cisco’s exam topics for changes. Finish with objective-mapped practice and a timed run. See SESA (300-720) →

Frequently asked questions

What is the 300-715 SISE exam?
300-715 SISE is “Implementing and Configuring Cisco Identity Services Engine,” a CCNP Security concentration exam. It tests deploying and configuring Cisco ISE — architecture and deployment, policy enforcement (802.1X, MAB, TrustSec), Web Auth and guest services, profiler, BYOD, endpoint compliance, and network access device administration.
Is the 300-715 exam changing to v1.2?
Yes. Cisco is updating the exam from v1.1 to v1.2. The last day to test v1.1 is August 26, 2026, and the first day for v1.2 is August 27, 2026. This page reflects the current v1.1 blueprint; if you’re scheduling near that date, confirm which version you’ll sit and review Cisco’s exam topics.
Is 300-715 a CCNP exam by itself?
SISE is a CCNP Security concentration exam. To earn CCNP Security you pass the SCOR 350-701 core plus one concentration such as SISE. Passing SISE on its own also earns the Cisco Certified Specialist – Security Identity Management Implementation credential.
What are the exam domains and weights?
Seven weighted domains (v1.1) that sum to 100%: Architecture and Deployment (10%), Policy Enforcement (25%, the heaviest), Web Auth and Guest Services (15%), Profiler (15%), BYOD (15%), Endpoint Compliance (10%), and Network Access Device Administration (10%).
How long is the exam?
The exam runs 90 minutes. It uses a scaled score, and Cisco does not publish a fixed public cut score. Confirm current details on Cisco’s exam page before scheduling.

Start your free 24-hour 300-715 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all seven SISE domains. No credit card required.

Start free trial →