Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 3

4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 5)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts
25%of the exam

Questions 21–25

  1. 21application · medium

    A network team wants to use ISE as the central AAA server for all administrative access to Cisco devices. They need to ensure that all administrative sessions are logged for compliance. They also want to use TACACS+ for command authorization. What must they configure in ISE to meet both requirements?

    Select an answer first
  2. 22expert · hard

    A large enterprise has deployed ISE for TACACS+ device administration. They have multiple policy sets: one for 'Core' devices, one for 'Edge' devices, and a default. A senior engineer reports that they can authenticate to a core switch but cannot execute 'reload' even though they are in the 'Network-Admin' group, which is supposed to have full access. The ISE logs show that the authorization policy matched the 'Network-Admin' group and returned a command set that includes 'reload'. However, the device still denies the command. What is the most likely cause?

    Select an answer first
  3. 23expert · hard

    An organization uses ISE for TACACS+ device administration. They have two policy sets: 'Device-Admin' and 'Default'. The 'Device-Admin' policy set has a condition that matches the device IP address range. A new device was added, and the administrator can authenticate but receives a 'denied' response from ISE. The ISE logs show that the request matched the 'Default' policy set, which has a deny result. What is the most likely reason?

    Select an answer first
  4. 24expert · hard

    A network administrator is configuring ISE for TACACS+ device administration. They want to allow a group of operators to run 'show' commands and 'clear counters' on interfaces, but they must not be able to run 'configure terminal'. They create a command set with 'show' and 'clear counters' and assign it to the operators group. However, the operators can still enter configuration mode. What is the most likely cause?

    Select an answer first
  5. 25expert · hard

    A security auditor requires proof that a specific administrator executed a 'reload' command on a core router at a specific time. The organization uses ISE for TACACS+ device administration. The ISE logs show that the administrator authenticated and was authorized, but there is no record of the 'reload' command. What is the most likely reason?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.