🔥 3-day streak
Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715)27 / 139
Question 27 of 139
An ISE administrator has built an authorization policy set for wired 802.1X. The policy set contains these rules in order: (1) 'Employee_Full' matches AD group 'Domain Users' and permits full access, (2) 'Contractor_Limited' matches AD group 'Contractors' and applies a restricted dACL. A user who is a member of both 'Domain Users' and 'Contractors' in Active Directory authenticates successfully. The administrator expects this user to receive the restricted contractor access but instead sees full access being granted. What is the cause of this behavior, and how should it be corrected?
Reviewed for accuracy · Report an issueNext question