
CCIE Security
Domain 4Objective 7
4.7 Cisco ISE Integration with External Identity Sources CCIE-SECURITY Practice Questions (Page 8)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
10concepts
25%of the exam
Questions 36–40
- 36
A company uses Cisco ISE with Active Directory for wireless authentication. They want to grant different access levels based on AD group membership. Which of the following is the correct way to use AD groups in authorization policies?
Select an answer first - 37
A managed service provider (MSP) uses Cisco ISE to provide network access for multiple clients. One client has an existing RADIUS server that already handles authentication for their legacy systems. The MSP wants to use that RADIUS server as an identity source in ISE. What is the appropriate approach?
Select an answer first - 38
You need to configure an external RADIUS identity source in ISE. The RADIUS server is at 192.168.10.5 and uses the shared secret 'SecureKey123'. The RADIUS server listens on the default authentication port. What configuration should you use?
Select an answer first - 39
Cisco ISE is configured to use an external RADIUS server for authentication. A user attempts to authenticate. What happens when ISE receives the authentication request?
Select an answer first - 40
A university uses an existing OpenLDAP directory for student accounts. The network team is integrating Cisco ISE for 802.1X wireless authentication. They want to authenticate students against LDAP but also need to retrieve the 'department' attribute to enforce different authorization policies for engineering vs. liberal arts students. The LDAP server is at ldap.university.edu, base DN is dc=university,dc=edu. What should the administrator configure in the LDAP identity source to meet these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.