
CCIE Security
Domain 4Objective 3
4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 9)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
25%of the exam
Questions 41–45
- 41
A network admin is troubleshooting TACACS+ authentication to a Cisco switch. The switch is configured with 'aaa authentication login default group tacacs+ local'. ISE is configured with a device administration policy set that matches the switch's IP and the user's group. The user can authenticate, but when they try to run 'show running-config', they get 'Authorization failed'. Other users in the same group can run 'show running-config'. What is the most likely cause?
Select an answer first - 42
A service provider manages customer edge devices. They want to use Cisco ISE for administrative access, but they have a constraint: some older devices only support RADIUS for AAA, not TACACS+. They need to provide per-command authorization for those devices. What is the best approach?
Select an answer first - 43
A compliance team needs to prove that a specific administrator did not execute a 'reload' command on a core router. The organization uses ISE for TACACS+ device administration. Which evidence would be most reliable?
Select an answer first - 44
An organization has multiple ISE policy sets for device administration. They notice that some users are getting authorization denied for commands that should be allowed. They suspect the policy set order is causing incorrect matches. What is the best practice for ordering policy sets in ISE?
Select an answer first - 45
A network admin is setting up TACACS+ device administration with ISE. They want to support both PAP and CHAP authentication. However, they notice that when a user authenticates with CHAP, the ISE logs show the password as encrypted, but when using PAP, it shows in clear text. They are concerned about security. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.