300-715 · Question #329
An administrator must configure Cisco ISE to authenticate a user accessing a Cisco Adaptive Security Appliance firewall using SSH. The solution must meet these requirements: - The local Cisco ISE…
The correct answer is D. Configure TACACS command sets. E. Configure an authorization profile. To authenticate users accessing a Cisco ASA via SSH using Cisco ISE's local database and validate their commands, configure TACACS command sets for granular control and an authorization profile to apply these command sets.
Question
An administrator must configure Cisco ISE to authenticate a user accessing a Cisco Adaptive Security Appliance firewall using SSH. The solution must meet these requirements:
- The local Cisco ISE database must be used for user authentication
- ASA commands run by users must be validated
The configurations were performed:
- added the Cisco Adaptive Security Appliance firewall
- configured user accounts
- enabled Device Admin Service in Cisco ISE
- configured a TACACS profile
- configured an authorization policy
- configured the Cisco Adaptive Security Appliance firewall for
authentication and authorization Which two actions must be taken in Cisco ISE? (Choose two.)
Options
- AEnable local authentication.
- BConfigure a user identity group.
- CConfigure an authentication profile.
- DConfigure TACACS command sets.
- EConfigure an authorization profile.
How the community answered
(31 responses)- A3% (1)
- B16% (5)
- C10% (3)
- D71% (22)
Why each option
To authenticate users accessing a Cisco ASA via SSH using Cisco ISE's local database and validate their commands, configure TACACS command sets for granular control and an authorization profile to apply these command sets.
Enabling local authentication is a fundamental setup step, but with 'Device Admin Service enabled' and 'user accounts configured', it's likely already in place and not a distinct missing action for *command validation*.
Configuring a user identity group is part of user management, implied by 'configured user accounts', but it's not a missing action specifically for enabling command validation or privilege assignment via TACACS+.
An authentication profile defines how ISE authenticates users; while crucial, the problem implies authentication against the local ISE database is already configured, focusing on missing steps for *command validation* and *privilege assignment*.
To validate ASA commands run by users, specific TACACS command sets must be configured in Cisco ISE. These command sets define which commands or command patterns are allowed or denied for different user groups, providing granular command authorization.
An authorization profile is necessary to define the authorization attributes, such as shell profiles, privilege levels, or command sets, that Cisco ISE sends back to the ASA after a user successfully authenticates. This profile dictates the user's specific access rights and command privileges on the firewall.
Concept tested: Cisco ISE TACACS+ command authorization
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/b_ISE_admin_3_1_chapter_0110.html
Topics
Community Discussion
No community discussion yet for this question.