300-715 · Question #101
Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )
The correct answer is B. Device Admin Service C. Device Administration License. To enable the TACACS+ feature on Cisco ISE, the Device Admin Service must be enabled on a Policy Service Node and a Device Administration License is required.
Question
Which two features should be used on Cisco ISE to enable the TACACS+ feature? (Choose two )
Options
- AExternal TACACS Servers
- BDevice Admin Service
- CDevice Administration License
- DServer Sequence
- ECommand Sets
How the community answered
(37 responses)- A3% (1)
- B86% (32)
- D8% (3)
- E3% (1)
Why each option
To enable the TACACS+ feature on Cisco ISE, the Device Admin Service must be enabled on a Policy Service Node and a Device Administration License is required.
External TACACS Servers are configured if ISE is acting as a proxy to forward requests, not to enable ISE's own TACACS+ functionality.
To enable TACACS+ functionality on Cisco ISE for device administration, the 'Device Admin Service' must be enabled on the Policy Service Node, as this service handles the TACACS+ authentication and authorization requests.
A 'Device Administration License' is required to unlock and utilize the TACACS+ feature within Cisco ISE, allowing for secure management of network devices.
Server Sequence defines the order in which identity sources are checked, which is part of policy configuration, not a feature enabling TACACS+ itself.
Command Sets are used for granular TACACS+ authorization (what commands an administrator can run), which is configured *after* the TACACS+ feature is enabled.
Concept tested: Cisco ISE TACACS+ Enabling and Licensing
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/m_device_administration.html
Topics
Community Discussion
No community discussion yet for this question.