Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Cisco
Exam Format
Registration
Validity
300-715 Exam Topics and Domains
300-715 is organized into 7 weighted domains. Expect to work with Accounting, Device registration, Guest VLAN, MAB fallback, and more.
Architecture and Deployment
Configure personas
- Configure and manage ISE personas in distributed deployments
- Understand persona limitations and incompatibilities
- Design high availability for each persona type
Describe deployment options
- Select appropriate deployment model based on requirements
- Understand deployment limitations and best practices
Describe hardware and virtual machine performance specifications
- Size ISE deployment based on endpoint count and throughput
- Understand VM requirements for different deployment sizes
Describe zero-touch provisioning
- Implement zero-touch provisioning for ISE nodes
- Configure network infrastructure for ZTP support
Policy Enforcement
Configure native AD and LDAP
- Integrate ISE with Active Directory domains
- Configure LDAP as external identity source
- Troubleshoot authentication failures
Describe identity store options
- Select appropriate identity stores for use cases
- Configure identity source sequences
- Implement certificate-based authentication
Configure wireless network access using 802.1X
- Configure WLC for 802.1X authentication
- Implement EAP methods for wireless
- Configure dynamic authorization
Configure wired network access using 802.1X and IBNS 2.0
- Implement IBNS 2.0 deployment modes
- Configure flexible authentication
- Design phased deployment strategy
Implement MAB
- Configure MAB for non-802.1X devices
- Integrate MAB with profiling
- Secure MAB deployments
Configure Cisco TrustSec
- Design SGT architecture
- Configure SGT assignment methods
- Implement SGACL policies
Configure policies including authentication and authorization profiles
- Create policy sets for different use cases
- Configure authentication and authorization policies
- Implement exception handling
Web Auth and Guest Services
Configure web authentication
- Implement central web authentication
- Configure local web authentication
- Customize portal pages
Configure guest access services
- Design guest access workflows
- Configure guest account settings
- Implement guest notifications
Configure sponsor and guest portals
- Configure sponsor portals
- Customize guest portals
- Implement social login
Profiler
Implement profiler services
- Configure profiler service
- Create custom profiling policies
- Implement logical profiles
Implement probes
- Configure profiler probes
- Optimize probe deployment
- Troubleshoot probe issues
Implement CoA
- Configure CoA for profile changes
- Implement CoA in authorization policies
- Troubleshoot CoA issues
Configure endpoint identity management
- Manage endpoint database
- Configure endpoint groups
- Implement purge policies
BYOD
Describe Cisco BYOD functionality
- Understand BYOD architecture
- Design BYOD workflows
- Select appropriate BYOD model
Configure BYOD device on-boarding using internal CA
- Configure ISE internal CA
- Implement BYOD onboarding
- Configure network devices for BYOD
Configure certificates for BYOD
- Design certificate policies
- Configure certificate templates
- Implement certificate lifecycle
Configure block list/allow list
- Configure device access lists
- Implement lost device policies
- Manage device lifecycle
Endpoint Compliance
Describe endpoint compliance, posture services, and client provisioning
- Understand posture assessment architecture
- Select appropriate posture methods
- Design compliance policies
Configure posture conditions and policy, and client provisioning
- Configure posture conditions
- Create posture policies
- Implement client provisioning
Configure the compliance module
- Configure compliance integrations
- Implement threat-centric NAC
- Deploy vulnerability assessment
Configure posture agents and operational modes
- Configure posture agents
- Select operational modes
- Troubleshoot agent issues
Describe supplicant, supplicant options, authenticator, and server
- Understand 802.1X architecture
- Configure supplicant settings
- Troubleshoot authentication issues
Network Access Device Administration
Compare AAA protocols
- Understand AAA protocol differences
- Select appropriate protocol for use case
- Configure protocol-specific features
Configure TACACS+ device administration and command authorization
- Configure TACACS+ for device administration
- Implement command authorization
- Create device administration policies
How do I earn this certification?
Passing 300-715 earns the CCNP Security certification. It sits in the Security track.
- CCIE Security Lab - CCIE Security Infrastructure Lab Exam
- 350-901 - DEVCOR - Developing Applications Using Cisco Core Platforms and APIs
- 300-710 - SNCF - Securing Networks with Cisco FirepowerFirewall and IPS expertise
- 300-720 - SESA - Securing Email with Cisco Email Security ApplianceEmail security specialization
- 300-725 - SWSA - Securing the Web with Cisco Web Security ApplianceWeb security focus
- 300-730 - SVPN - Implementing Secure Solutions with Virtual Private NetworksVPN and remote access security
- 300-735 - SAUTO - Automating Cisco Security SolutionsSecurity automation and orchestration
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for 300-715 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2023-02-24
- Announcement date: 2023-01-15
- pxGrid 3.0 3.0 New API capabilities and WebSocket support likely in next exam update ⢠Release date: 2024-02-01
- ISE REST APIs Enhanced in 3.3 Automation topics may be expanded ⢠Release date: 2024-09-01
- Zero Touch Provisioning Enhanced in v1.1 Added as new topic in exam v1.1 ⢠Release date: 2023-02-24
Who should take this exam?
This exam is typically taken by Network Security Engineers and Network Administrators.
- Understanding of network security concepts
- Basic knowledge of Cisco networking devices
- Familiarity with 802.1X and RADIUS
- Experience with identity management concepts
- Knowledge of Active Directory and LDAP