
CCIE Security
Domain 4Objective 3
4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 8)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
25%of the exam
Questions 36–40
- 36
A network operations team manages a fleet of Cisco IOS routers and switches. They want to enforce per-command authorization for network administrators, allowing only the 'show' commands for junior staff and full configuration access for senior staff. They also need detailed logs of every command executed for compliance audits. Which approach should they implement?
Select an answer first - 37
An organization is deploying Cisco ISE as the AAA server for administrative access to their network devices. They want to ensure that all administrative actions are logged for compliance, and they also want to separate authentication, authorization, and accounting functions. Which protocol should they use?
Select an answer first - 38
A network team needs to provide different levels of administrative access based on the time of day. For example, during business hours, all administrators can configure devices, but after hours, only senior administrators can make changes. They use Cisco ISE for device administration. How can they implement this?
Select an answer first - 39
A user is unable to authenticate to a Cisco router using TACACS+ through ISE. The router's debug output shows 'TACACS+ server not responding'. What is the most likely cause?
Select an answer first - 40
A large enterprise is migrating from local device administration to centralized AAA using Cisco ISE. They have multiple device types (routers, switches, firewalls) and multiple admin groups (NOC, SOC, Engineering). They require: 1) Per-command authorization for CLI, 2) Detailed accounting for compliance, 3) Different policies per device group, 4) The ability to override command authorization for emergency break-glass access. They are considering TACACS+ vs RADIUS. Which design best meets all requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.