Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 3

4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 6)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts
25%of the exam

Questions 26–30

  1. 26expert · hard

    A company is using ISE for device administration with RADIUS for a set of older switches. They are experiencing intermittent authentication failures. The ISE logs show that the RADIUS requests are being received but sometimes the response is not sent back to the device. The network team suspects a firewall issue. What is the most likely cause?

    Select an answer first
  2. 27expert · hard

    An organization wants to integrate ISE with Cisco DNA Center for network device management. They want to use ISE for administrative access to the devices managed by DNA Center. The DNA Center uses its own credentials to access devices, but the organization wants to enforce ISE policies for any direct CLI access to the devices. What is the best approach?

    Select an answer first
  3. 28application · medium

    A small enterprise wants to use Cisco ISE to authenticate administrators on their Cisco switches. They only need authentication (no per-command authorization) and they want to use the same RADIUS infrastructure they already have for wireless. The security team is concerned about the lack of encryption for some RADIUS attributes. What should they do to meet the requirement while addressing the concern?

    Select an answer first
  4. 29application · medium

    An organization has multiple Cisco devices and wants to use ISE for device administration. They need to create a policy that allows only senior network engineers to configure devices in the 'core' device group, while junior staff can only view configurations. They also want to ensure that if a user is not in the correct group, they are denied access. What is the most efficient way to implement this in ISE?

    Select an answer first
  5. 30application · medium

    A company is configuring ISE for device administration on Cisco routers. They want to use Active Directory as the identity source. The network devices are configured with 'aaa authentication login default group tacacs+'. During testing, authentication fails. The ISE logs show that the user exists in AD but the authentication attempt is rejected. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.