
CCIE Security
Domain 4Objective 4
4.4 AAA for Network Access with 802.1X and MAB Using Cisco ISE CCIE-SECURITY Practice Questions (Page 6)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
11concepts
25%of the exam
Questions 26–30
- 26
A printer fails MAB authentication. The switch sends the MAC address to ISE, but ISE returns 'Authentication failed'. The printer's MAC is correctly listed in the endpoint database. What is the most likely cause?
Select an answer first - 27
A large enterprise is rolling out 802.1X across multiple sites. They have a mix of Windows and macOS devices. Some macOS users report that they can authenticate but are placed in the wrong VLAN. The ISE logs show successful authentication, but the authorization result is not what is expected. The admin suspects the issue is with the authorization policy. What is the best approach to diagnose the issue?
Select an answer first - 28
A company has a complex authorization policy with multiple rules. They want to ensure that a specific group of users (e.g., 'Contractors') always gets a restricted dACL, regardless of other conditions. However, they also have a rule that assigns a 'Full Access' profile to users in the 'Employees' group. A contractor who is also in the 'Employees' group is currently getting 'Full Access'. What is the best way to fix this?
Select an answer first - 29
A network admin is configuring an authorization profile for a new network device that uses a vendor-specific attribute (VSA) for VLAN assignment. The device does not support the standard Tunnel-Private-Group-ID attribute. The admin needs to ensure the correct VSA is sent. What should the admin do in ISE?
Select an answer first - 30
A company uses downloadable ACLs for guest access. They update the dACL in ISE to block a new malicious website. However, existing guest sessions are still able to access the website. What is the most likely reason and what should be done?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.