Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 4

4.4 AAA for Network Access with 802.1X and MAB Using Cisco ISE CCIE-SECURITY Practice Questions (Page 11)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)

60questions here
12free pages
11concepts
25%of the exam

Questions 51–55

  1. 51expert · hard

    A user is authenticated via 802.1X and receives a dACL that should permit only HTTP and HTTPS. However, the user can also access other ports. The dACL is correctly defined in ISE. What is the most likely cause?

    Select an answer first
  2. 52application · medium

    A manufacturing plant has IP phones and barcode scanners that lack 802.1X supplicants. You configure MAB on the switch ports. The devices authenticate successfully, but they all receive the default 'voice' VLAN instead of being split into separate VLANs for phones and scanners. What should you do to assign different VLANs?

    Select an answer first
  3. 53expert · hard

    An administrator sends a CoA 'Reauth' to a session, but the switch does not re-authenticate the user. The switch logs show 'CoA ACK' but no re-authentication. What is the most likely cause?

    Select an answer first
  4. 54application · medium

    A university is implementing ISE as the RADIUS server for 802.1X on campus switches. They need to ensure that only users from the Active Directory domain 'ad.university.edu' can authenticate, and they must receive a specific downloadable ACL. Which ISE configuration is required?

    Select an answer first
  5. 55application · medium

    A company wants to enforce different access policies for employees and contractors. Both groups authenticate via 802.1X. The contractor policy should place them in a restricted VLAN and also apply a dACL. Employees get full access. What is the most efficient way to implement this in ISE?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.