Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) · Domain 7 · 10% of exam

Network Access Device Administration

Drill 14 practice questions focused entirely on Network Access Device Administration for the Cisco 300-715 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer14 questions
Question 1 of 14

A security auditor requests that every command entered by network administrators on Cisco IOS switches be recorded in ISE so that a complete audit trail is available, including who ran each command and when. Device administration via TACACS+ is already working for authentication and command authorization. Which additional configuration on the IOS switch is required to satisfy the auditor's requirement?

Reviewed for accuracy · Report an issue
Question 2 of 14

A network administrator configures ISE as a TACACS+ server for device administration on a set of IOS switches. Command authorization is enabled with 'aaa authorization commands 15 default group ISE-TACACS'. During a maintenance window, all ISE PSNs become unreachable. When the administrator logs in via the console (already authenticated locally), every privilege-level 15 command is rejected. What single configuration change on the switch will allow authorized local commands to execute when the TACACS+ servers are unreachable?

Reviewed for accuracy · Report an issue
Question 3 of 14

A network administrator is configuring TACACS+ device administration in Cisco ISE. Senior engineers who belong to the Active Directory group 'NetOps-Senior' must be granted full privilege-15 shell access with no command restrictions, while junior engineers in 'NetOps-Junior' should log in at privilege 15 but only be permitted to run 'show' commands. Both groups authenticate against the same AD join point and connect to the same IOS switches. Which combination of ISE Device Admin policy components correctly enforces this differentiated access?

Reviewed for accuracy · Report an issue
Question 4 of 14

A network administrator wants junior engineers to have full command access on access-layer switches but only read-only (show) commands on core routers. Both device types are already defined in ISE with distinct Network Device Groups. The engineers all belong to a single AD group used in one TACACS+ authorization policy set. What is the MOST effective way to enforce these differentiated command privileges in ISE Device Administration?

Reviewed for accuracy · Report an issue
Question 5 of 14

A network administrator creates a TACACS+ command set in ISE for junior operators. The command set explicitly permits 'show' and 'ping' commands. The administrator leaves the 'Permit any command that is not listed below' checkbox unchecked and assigns the command set through an authorization policy. When a junior operator logs into an IOS switch and types 'configure terminal', what happens?

Reviewed for accuracy · Report an issue
Question 6 of 14

A network administrator is configuring TACACS+ device administration on Cisco ISE. Junior operators must be able to log into IOS switches, land directly in privileged EXEC (level 15), but only be permitted to run 'show' commands and 'ping' — all other commands must be denied. Which combination of TACACS+ policy result components should be assigned to the operator authorization rule?

Reviewed for accuracy · Report an issue
Question 7 of 14

A network engineer configures ISE for TACACS+ device administration. Network device groups, a TACACS+ device admin policy set, shell profiles, and command sets are all created correctly. However, when administrators attempt to log in to a switch using TACACS+, authentication fails and no live logs appear in the ISE Device Administration reports. RADIUS-based network access on the same deployment works fine. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 8 of 14

A network engineer configures TACACS+ device administration in Cisco ISE for a group of IOS switches. A command set named 'NetOps-Commands' explicitly permits 'show' and 'configure terminal' but includes no other entries, and the 'Unmatched Commands' setting in that command set is left as its default. A technician logs in, is authorized by the shell profile, and successfully runs 'show running-config'. However, when the technician attempts to run 'reload', the command is rejected. What is the reason 'reload' is denied?

Reviewed for accuracy · Report an issue
Question 9 of 14

An engineer is configuring TACACS+ device administration in ISE for a group of switches. The authorization policy rule for the 'JuniorNetOps' group references two command sets: 'CS-ShowOnly' (permits 'show' commands, denies all others) and 'CS-IntConfig' (permits 'configure terminal' and 'interface' commands). Both command sets are added to the same authorization result. When a junior engineer runs 'interface GigabitEthernet1/0/1', the command is permitted. When they run 'reload', it is denied. How does ISE evaluate multiple command sets attached to a single authorization result?

Reviewed for accuracy · Report an issue
Question 10 of 14

A network administrator is configuring TACACS+ device administration in Cisco ISE for a Cisco Wireless LAN Controller (WLC). Help desk staff must log in to the WLC and receive read-only (MONITOR) access automatically upon authentication, without being prompted for further privilege changes. The WLC uses vendor-specific TACACS+ custom attributes to convey the role. Where in the ISE TACACS+ policy result should the administrator define the attribute 'role1=MONITOR' so it is returned during the session authorization?

Reviewed for accuracy · Report an issue
Question 11 of 14

A network administrator configures a TACACS+ device administration policy in ISE for a group of junior engineers. The shell profile assigns a 'Default Privilege' of 1 and a 'Maximum Privilege' of 7. When a junior engineer logs into a Cisco IOS switch and issues the 'enable 7' command, what is the resulting behavior?

Reviewed for accuracy · Report an issue
Question 12 of 14

A network engineer is configuring ISE TACACS+ device administration for a group of IOS switches. Junior administrators should log in and immediately be placed into privileged EXEC mode (level 15) without typing the 'enable' command or a secondary enable password. Which ISE TACACS+ configuration element must the engineer configure to achieve this?

Reviewed for accuracy · Report an issue
Question 13 of 14

A network engineer is configuring TACACS+ device administration between Cisco ISE and a large campus core switch that generates a high volume of command authorization requests. To reduce the overhead of repeatedly opening and tearing down TCP connections for each AAA request, the engineer wants ISE and the NAD to reuse a single TCP connection to multiplex multiple TACACS+ sessions. Which configuration must be enabled on both the network device and the corresponding entry in ISE to achieve this?

Reviewed for accuracy · Report an issue
Question 14 of 14

A network administrator is designing device administration for a fleet of Cisco IOS routers and switches. Requirements include: encrypting the entire packet payload (not just the password), granular per-command authorization for network operators, and separating authentication, authorization, and accounting into independent functions. Which AAA protocol should be configured in Cisco ISE to meet all of these requirements?

Reviewed for accuracy · Report an issue

More 300-715 practice

Keep going with the other Cisco CCNP Security SISE — Implementing and Configuring Cisco Identity Services Engine (300-715) domains, or take a full timed mock exam.

← Back to 300-715 overview