
CCIE Security
Domain 4Objective 4
4.4 AAA for Network Access with 802.1X and MAB Using Cisco ISE CCIE-SECURITY Practice Questions (Page 5)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
11concepts
25%of the exam
Questions 21–25
- 21
In Cisco ISE, what is the purpose of exception rules in a policy set?
Select an answer first - 22
What is the primary function of an authorization profile in Cisco ISE?
Select an answer first - 23
A hospital is deploying 802.1X for wired nurse stations. The network team notices that some Windows PCs fail authentication intermittently, while others succeed. The ISE live logs show 'RADIUS Request' but no 'RADIUS Accept' for the failing PCs. The switch shows the port in 'unauthorized' state. Which two-step troubleshooting approach should the team take first to isolate the issue?
Select an answer first - 24
A user's role changes from employee to contractor, and the admin needs to update the user's network access to a more restrictive VLAN and dACL. The user is currently online. What is the most efficient way to apply the new policy?
Select an answer first - 25
A user reports that they cannot connect to the network via 802.1X. The switch shows the port in 'unauthorized' state. ISE logs show 'Authentication failed' for the user. What should the admin check first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.