
CCIE Security
Domain 4Objective 4
4.4 AAA for Network Access with 802.1X and MAB Using Cisco ISE CCIE-SECURITY Practice Questions (Page 10)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
11concepts
25%of the exam
Questions 46–50
- 46
An organization is deploying ISE for 802.1X. They have two ISE nodes in a deployment. The primary node is the policy administration node (PAN), and the secondary is a policy service node (PSN). They want to ensure that if the primary PSN fails, the switch can still authenticate users. What should they configure?
Select an answer first - 47
A company has an authorization profile that assigns a dACL to a group of users. After a policy change, the dACL is updated in ISE. However, existing sessions are still using the old dACL. What is the most efficient way to apply the new dACL to existing sessions?
Select an answer first - 48
A company uses ISE with Active Directory as the identity source. They want to allow only users who are members of the 'Network_Access' AD group to authenticate via 802.1X. They also have a local guest account for temporary visitors. How should they configure the authentication policy?
Select an answer first - 49
A network admin is troubleshooting an issue where a user is not receiving the correct dACL. The user authenticates successfully, but the switch applies a different ACL. The ISE authorization profile includes the Cisco VSA 'ip:inacl#100=Restricted'. The switch has a dACL named 'Restricted' configured. What is the most likely cause?
Select an answer first - 50
A company uses ISE to assign VLANs dynamically. They have a group of users that should be in VLAN 30, but after a recent change, they are getting VLAN 10. The authorization profile for that group is correct. What should you check first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.