Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 3

4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 7)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts
25%of the exam

Questions 31–35

  1. 31application · medium

    A security auditor requires a record of every command executed by administrators on Cisco network devices. The organization uses ISE for TACACS+ device administration. What must be enabled in ISE to meet this requirement?

    Select an answer first
  2. 32application · medium

    A network administrator wants to use ISE to manage administrative access to Cisco devices via the CLI, GUI, and API. They want to ensure that the same authentication and authorization policies apply across all three methods. What is the best approach?

    Select an answer first
  3. 33application · medium

    An administrator is troubleshooting why a user cannot log in to a Cisco switch using ISE TACACS+. The user's credentials are correct, and the switch can reach the ISE server. The ISE logs show that the authentication succeeded, but the authorization failed. What is the most likely cause?

    Select an answer first
  4. 34application · medium

    A company wants to allow a group of network operators to run only 'show' commands on Cisco routers, but they also need to allow them to use 'clear counters' on specific interfaces. They are using ISE for TACACS+ device administration. What is the best way to configure this?

    Select an answer first
  5. 35application · medium

    An organization is using ISE for device administration, but they have a legacy network device that only supports RADIUS for AAA. They need to authenticate administrators and provide basic authorization (e.g., allow or deny access to the device). They do not need per-command authorization. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.