🔥 3-day streak
Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715)127 / 139
Question 127 of 139

A network administrator wants junior engineers to have full command access on access-layer switches but only read-only (show) commands on core routers. Both device types are already defined in ISE with distinct Network Device Groups. The engineers all belong to a single AD group used in one TACACS+ authorization policy set. What is the MOST effective way to enforce these differentiated command privileges in ISE Device Administration?

Reviewed for accuracy · Report an issueNext question