300-715 · Question #280
An engineer is configuring a new Cisco ISE node. The Device Admin service must run on this node to handle authentication requests for network device access via TACACS+. Which persona must be enabled…
The correct answer is C. Policy Service. To handle network device access authentication requests via TACACS+ using the Device Admin service on a Cisco ISE node, the Policy Service persona must be enabled.
Question
An engineer is configuring a new Cisco ISE node. The Device Admin service must run on this node to handle authentication requests for network device access via TACACS+. Which persona must be enabled on this node to perform this function?
Options
- ApxGrid
- BAdministration
- CPolicy Service
- DMonitoring
How the community answered
(48 responses)- A2% (1)
- B2% (1)
- C90% (43)
- D6% (3)
Why each option
To handle network device access authentication requests via TACACS+ using the Device Admin service on a Cisco ISE node, the Policy Service persona must be enabled.
The pxGrid persona provides a platform for integration with other security products, not direct TACACS+ authentication processing.
The Administration persona provides the web-based user interface and manages ISE configuration, but does not process authentication requests.
The Policy Service persona is responsible for evaluating authentication and authorization policies, including those for network device administration (TACACS+). When the Device Admin service is enabled on an ISE node, it primarily uses the Policy Service persona to process authentication and authorization requests from network devices.
The Monitoring persona collects and stores logs and provides reporting, but it does not evaluate policies or process live authentication requests.
Concept tested: Cisco ISE personas and TACACS+
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_010.html
Topics
Community Discussion
No community discussion yet for this question.