300-715 · Question #271
Due to a recent network incident, all access to network devices must be centrally logged and tracked in Cisco ISE. On which nodes must the Device Admin service be enabled?
The correct answer is B. each PSN. For Cisco ISE to provide central logging and tracking of network device access via Device Admin, the Device Admin service must be enabled on each Policy Service Node (PSN).
Question
Due to a recent network incident, all access to network devices must be centrally logged and tracked in Cisco ISE. On which nodes must the Device Admin service be enabled?
Options
- Aone PAN
- Beach PSN
- Ceach PAN
- Done PSN
How the community answered
(26 responses)- A4% (1)
- B92% (24)
- D4% (1)
Why each option
For Cisco ISE to provide central logging and tracking of network device access via Device Admin, the Device Admin service must be enabled on each Policy Service Node (PSN).
The PAN (Primary Administration Node) handles administration and database services, but not the runtime TACACS+ services for device administration.
The Device Admin service, also known as TACACS+ service, runs on Policy Service Nodes (PSNs). When network devices (like switches, routers, firewalls) authenticate and authorize administrators via TACACS+, they communicate with the PSNs. Therefore, to ensure redundancy and distribute the load for all access to network devices, the Device Admin service should be enabled on each PSN that will handle these requests.
PANs do not host the Device Admin (TACACS+) runtime service.
While a PSN can host the Device Admin service, enabling it on only one PSN would create a single point of failure and limit scalability for handling all network device access requests across the network.
Concept tested: Cisco ISE Device Admin (TACACS+) service placement
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_011.html
Topics
Community Discussion
No community discussion yet for this question.