
CCIE Security
Domain 4Objective 12
4.12 Certification-Based Authentication Using Cisco ISE CCIE-SECURITY Practice Questions (Page 9)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
25%of the exam
Questions 41–45
- 41
A company uses PEAP with MSCHAPv2 for wireless authentication. They want to add certificate-based authentication for users without changing the client configuration. They have an internal CA and want to use the same PEAP method but with client certificates. What is the best way to achieve this in Cisco ISE?
Select an answer first - 42
An ISE admin is troubleshooting a certificate-based authentication failure. The logs show 'Authentication failed: Certificate validation failed - OCSP check failed'. The client certificate is valid and the trust chain is correct. What is the most likely cause?
Select an answer first - 43
A company is considering moving from username/password authentication to certificate-based authentication for their VPN remote access. They want to reduce the risk of credential theft and phishing. They also want to ensure that only company-managed devices can connect. What is the primary benefit of using certificate-based authentication in this scenario?
Select an answer first - 44
An organization wants to automatically enroll certificates to Windows laptops using SCEP. They have a Microsoft NDES server. The ISE admin needs to configure the certificate provisioning profile in ISE. What is a required configuration step?
Select an answer first - 45
During EAP-TLS authentication, ISE receives a client certificate. The admin has configured the authentication policy to use 'Certificate Authentication' and has imported the root CA certificate. However, authentication fails with 'Certificate chain validation failed'. What should the admin check first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.