Cisco 300-715 SISE Identity Services Engine Practice Exam
Cover the full 300-715 v1.1 blueprint — ISE architecture and deployment, policy enforcement, Web Auth and guest services, profiler, BYOD, endpoint compliance, and network access device administration — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.
Start 24-hour free trial →300-715 exam at a glance
- Vendor
- Cisco
- Exam code
- 300-715 (SISE)
- Full name
- Implementing and Configuring Cisco Identity Services Engine
- Product
- Cisco Identity Services Engine (ISE)
- Level
- Professional
- Blueprint
- v1.1 (v1.2 begins August 27, 2026)
- Duration
- 90 minutes
- Role in CCNP
- CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
- Also earns
- Cisco Certified Specialist – Security Identity Management Implementation
- Domains
- Seven, with published weights (see below); they sum to 100%
- Prerequisites
- None formally required; 802.1X, RADIUS/TACACS+, and switching/wireless knowledge is recommended
- Delivery
- Pearson VUE; test center or online proctored
Sources: Cisco — SISE (300-715) exam page · Cisco — official SISE v1.1 exam topics (PDF). Verify current details with Cisco before scheduling.
About the Cisco 300-715 SISE exam
The 300-715 SISE exam validates the skills to implement and configure Cisco Identity Services Engine (ISE) — the identity and access-control platform that delivers consistent, secure access across wired, wireless, and VPN networks. It covers ISE architecture and deployment, policy enforcement with 802.1X/MAB/TrustSec, Web Auth and guest services, profiling, BYOD onboarding, posture/endpoint compliance, and device administration. For how certification exams work generally, see the certification study guides in our Learning Hub.
SISE is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SISE being the identity/access option. Passing SISE on its own also earns the Cisco Certified Specialist – Security Identity Management Implementation credential. ISE identity underpins zero-trust access in SCAZT (300-740) and feeds identity to firewalls in SNCF (300-710).
Every PowerKram practice question maps to one of the seven weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.
300-715 exam domains and weights (v1.1)
Cisco publishes seven weighted domains for the 300-715 v1.1 exam, and they sum to 100%. Policy Enforcement is by far the heaviest at 25% — roughly a quarter of the exam — so make 802.1X, MAB, identity stores, TrustSec, and authorization policy your priority, then round out onboarding, profiling, and posture. Confirm the current weights on Cisco’s exam topics before scheduling.
Configure ISE personas (PAN, MnT, PSN, pxGrid); deployment options (standalone vs distributed); hardware and virtual-machine performance specs; and zero-touch provisioning.
Native AD and LDAP; identity stores (LDAP, AD, PKI, MFA, local, SAML IdP, REST ID); wireless and wired 802.1X (IBNS 2.0 monitor/low-impact/closed modes); MAB; Cisco TrustSec; and authentication/authorization policies and profiles. The single heaviest domain.
Configure web authentication; guest access services; and sponsor and guest portals for visitor onboarding.
Implement profiler services and probes; Change of Authorization (CoA); and endpoint identity management to classify and control devices dynamically.
Cisco BYOD functionality (use cases, components, flow); device onboarding using the internal CA with Cisco switches and wireless LAN controllers; certificates for BYOD; and block/allow lists.
Posture services and client provisioning; posture conditions and policy; the compliance module; posture agents and operational modes; and the supplicant/authenticator/server model.
Compare AAA protocols (RADIUS vs TACACS+); and configure TACACS+ device administration and command authorization for network-device management.
Source: Cisco — official SISE v1.1 (300-715) exam topics (PDF). Weights are Cisco’s and sum to 100%. Note a v1.2 update begins August 27, 2026; verify the current edition before scheduling.
Who the 300-715 exam is for
SISE is aimed at engineers who build identity-based network access control:
- Network and security engineers deploying Cisco ISE for wired, wireless, and VPN access control.
- Identity and access specialists configuring 802.1X, MAB, TrustSec, and authorization policy.
- NAC / endpoint teams running profiling, BYOD onboarding, and posture compliance.
- CCNP Security candidates choosing the identity concentration alongside the SCOR 350-701 core.
Extend identity into zero-trust access with SCAZT (300-740), into firewall policy with SNCF (300-710), or pair it with email security in SESA (300-720). For where identity/access skills lead, see the cybersecurity career paths in our Career Hub.
What this 300-715 practice exam delivers
Learn mode
Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for policy-enforcement questions where authentication vs authorization order matters.
Exam mode
Timed, full-length simulation spanning all seven domains at the real 90-minute pace — so test day feels familiar.
Source-linked explanations
Every answer links to Cisco’s own SISE exam material, so you can verify each ISE configuration and policy choice against the source.
Score by weighted domain
Results break down across the seven weighted domains so you can see exactly which ISE area needs more work.
Sample 300-715 practice questions
Ten free questions across the 300-715 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.
Which ISE persona is responsible for all administration and configuration through the primary web GUI?
- The Policy Administration Node (PAN)
- The Monitoring node (MnT)
- The Policy Service Node (PSN)
- The pxGrid node
Show answer & explanation
Correct: A. The Policy Administration Node (PAN) provides the single administrative interface for configuration and policy management across the deployment. Understanding the four personas (PAN, MnT, PSN, pxGrid) is core to the architecture domain.
Why not the others: the MnT node (B) handles logging, monitoring, and reporting; the PSN (C) makes policy decisions and handles authentication/authorization; the pxGrid node (D) shares context with other platforms — none is the admin GUI.
Source: Cisco — SISE: architecture & personas → Further reading: PowerKram — SCAZT (300-740) →A device without an 802.1X supplicant (e.g. a printer) must still be granted controlled network access via ISE. Which method fits?
- Disabling authentication on the port
- MAC Authentication Bypass (MAB)
- Assigning a static public IP
- Turning off the switch
Show answer & explanation
Correct: B. MAC Authentication Bypass authenticates endpoints that can’t do 802.1X by using their MAC address as the identity, so ISE can still apply an authorization policy (often combined with profiling). It’s the standard fallback for headless devices.
Why not the others: disabling authentication (A) removes control entirely; a static public IP (C) is unrelated to access control; and turning off the switch (D) denies all access.
Source: Cisco — SISE: policy enforcement (MAB) → Further reading: PowerKram — SNCF (300-710) →Which Cisco technology uses Security Group Tags (SGTs) to enforce access based on role rather than IP address?
- Spanning Tree Protocol
- HSRP
- Cisco TrustSec
- NetFlow
Show answer & explanation
Correct: C. Cisco TrustSec assigns Security Group Tags to traffic based on identity/role and enforces policy with those tags (SGACLs), decoupling access control from IP addressing — a named policy-enforcement topic in ISE.
Why not the others: Spanning Tree (A) prevents switching loops, HSRP (B) provides gateway redundancy, and NetFlow (D) exports traffic telemetry — none enforce role-based access.
Source: Cisco — SISE: TrustSec →During phased 802.1X rollout, which IBNS 2.0 mode allows traffic even when authentication fails, so you can observe without blocking users?
- Closed mode
- Low-impact mode
- Monitor mode (open)
- Maintenance mode
Show answer & explanation
Correct: C. Monitor mode (open authentication) lets all traffic through while still logging authentication results, so administrators can validate policy before enforcing — the first step in a low-risk 802.1X deployment. Low-impact and closed modes progressively tighten enforcement.
Why not the others: closed mode (A) blocks all non-authenticated traffic; low-impact mode (B) permits limited traffic via a pre-auth ACL but still restricts; and “maintenance mode” (D) is not an IBNS deployment mode.
Source: Cisco — SISE: wired 802.1X & IBNS 2.0 →Which ISE portal lets employees approve and create temporary guest accounts without administrator involvement?
- The sponsor portal
- The admin CLI
- The BIOS setup screen
- The switch console
Show answer & explanation
Correct: A. The sponsor portal lets authorized employees (sponsors) create and manage guest accounts, delegating visitor onboarding away from IT — a named guest-services capability alongside self-registration and hotspot portals.
Why not the others: the admin CLI (B), BIOS (C), and switch console (D) are not guest-sponsorship interfaces.
Source: Cisco — SISE: guest & sponsor portals →After ISE re-profiles a connected endpoint into a new group that changes its authorization, what mechanism applies the new access without the user reconnecting?
- A power cycle of the switch
- Change of Authorization (CoA)
- A DNS flush
- A new cable
Show answer & explanation
Correct: B. RADIUS Change of Authorization lets ISE push a new authorization (re-auth, VLAN/ACL change, or disconnect) to an active session — essential so profiling and posture results can dynamically adjust access in place.
Why not the others: a switch power cycle (A) and a new cable (D) disrupt the session rather than updating it gracefully, and a DNS flush (C) has nothing to do with authorization.
Source: Cisco — SISE: profiler & CoA →In native ISE BYOD onboarding, what does the internal Certificate Authority issue to each personal device?
- A dynamic public IP lease
- A physical smart card
- A one-time paper code only
- A unique client certificate for certificate-based authentication
Show answer & explanation
Correct: D. During BYOD onboarding, ISE’s internal CA issues a unique client certificate to the device so it can authenticate via EAP-TLS afterward — stronger and more manageable than shared passwords. Configuring the internal CA and BYOD certificates is an explicit objective.
Why not the others: a public IP lease (A) isn’t issued by a CA; a physical smart card (B) isn’t part of native onboarding; and a paper code alone (C) doesn’t provide certificate-based auth.
Source: Cisco — SISE: BYOD onboarding & certificates → Further reading: PowerKram — SCAZT (300-740) →Which ISE capability checks whether a connecting device meets requirements (AV running, patches, disk encryption) before granting full access?
- A traceroute
- An SNMP walk
- Posture assessment
- A ping sweep
Show answer & explanation
Correct: C. Posture assessment evaluates endpoint health against posture conditions/policy (via an agent or agentless), then allows, quarantines, or remediates based on compliance — the core of the endpoint-compliance domain.
Why not the others: a traceroute (A), SNMP walk (B), and ping sweep (D) are diagnostics that don’t assess device compliance.
Source: Cisco — SISE: posture & compliance →To control which CLI commands specific administrators can run on switches and routers, which AAA protocol does ISE use for device administration?
- SNMPv2c
- NTP
- ICMP
- TACACS+
Show answer & explanation
Correct: D. TACACS+ separates authentication, authorization, and accounting and supports per-command authorization, making it the protocol for device administration (privileged CLI control) — whereas RADIUS is typically used for network access. Comparing the two is an explicit objective.
Why not the others: SNMPv2c (A) is for monitoring/management data, NTP (B) syncs time, and ICMP (C) is for diagnostics — none provide command authorization.
Source: Cisco — SISE: device administration (TACACS+) → Further reading: PowerKram — SESA (300-720) →In an ISE authorization policy, what is ultimately returned to the network device to define what an authenticated user may access?
- A screensaver theme
- An authorization profile (e.g. VLAN, dACL, or SGT)
- A firmware image
- A DHCP lease time only
Show answer & explanation
Correct: B. The authorization profile is the result ISE returns — it bundles the permissions (VLAN assignment, downloadable ACL, Security Group Tag, and other attributes) the network device applies to the session. Authentication proves identity; the authorization profile defines access.
Why not the others: a screensaver theme (A), a firmware image (C), and a DHCP lease time (D) are not access-control results returned by an authorization policy.
Source: Cisco — SISE: authorization profiles →Keep going: Learning & Career resources
SISE is the identity/access concentration in the CCNP Security track. Two PowerKram hubs back this exam.
Deep dive: Cisco ISE, the CCNP Security path, and study strategy
What Cisco ISE does
Cisco Identity Services Engine is the policy engine for network access: it authenticates users and devices (802.1X, MAB, certificates), profiles what they are, checks their posture, and returns an authorization result (VLAN, dACL, or SGT) that the switch, WLC, or VPN enforces. The exam mirrors that flow — identity store → authentication → profiling/posture → authorization → enforcement — which is why Policy Enforcement dominates the blueprint. See SCAZT (300-740) →
How SISE fits CCNP Security
CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SISE is the identity/access concentration; secure cloud access via SCAZT (300-740), firewalls via SNCF (300-710), and email via SESA (300-720) are related options. Passing SISE alone also earns Cisco Certified Specialist – Security Identity Management Implementation. See SNCF (300-710) →
Realistic study path and the v1.2 change
Policy Enforcement is a quarter of the exam, so build a lab: stand up ISE personas, wire 802.1X and MAB on a switch, configure identity stores and authorization profiles, then layer in profiling, BYOD with the internal CA, and posture. Because a v1.2 blueprint begins August 27, 2026, candidates testing near that date should confirm their version and check Cisco’s exam topics for changes. Finish with objective-mapped practice and a timed run. See SESA (300-720) →
Frequently asked questions
What is the 300-715 SISE exam?
Is the 300-715 exam changing to v1.2?
Is 300-715 a CCNP exam by itself?
What are the exam domains and weights?
How long is the exam?
Start your free 24-hour 300-715 practice trial
Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all seven SISE domains. No credit card required.
Start free trial →