300-715 · Question #372
An administrator must enable helpdesk users to view users' information on wireless LAN controllers in a Cisco ISE environment. The solution must meet these requirements: - Authenticate the helpdesk…
The correct answer is B. Assign the Monitor role in the TACACS profile C. Configure an identity group. To grant helpdesk users access to the Monitor tab on a WLC via TACACS+, two things are needed. First, the TACACS profile must assign the Monitor role (Choice B), because the Monitor role is what grants read-only access to the WLC's Monitor tab - without it, ISE has no…
Question
An administrator must enable helpdesk users to view users' information on wireless LAN controllers in a Cisco ISE environment. The solution must meet these requirements:
- Authenticate the helpdesk users against the local ISE database.
- Allow the helpdesk users to access the Monitor tab tor the WLC.
These configurations were performed:
- added a wireless LAN controller
- configured user accounts
- enabled Device Admin Service in Cisco ISE
- configured a TACACS profile
- configured a policy set
- configured an authentication policy
- configured an authorization policy
Which two actions must be taken in Cisco ISE? (Choose two.)
Options
- AConfigure an authentication profile
- BAssign the Monitor role in the TACACS profile
- CConfigure an identity group.
- DAssign the Wireless role in the TACACS profile
- EConfigure TACACS command sets.
How the community answered
(55 responses)- A5% (3)
- B78% (43)
- D4% (2)
- E13% (7)
Explanation
To grant helpdesk users access to the Monitor tab on a WLC via TACACS+, two things are needed. First, the TACACS profile must assign the Monitor role (Choice B), because the Monitor role is what grants read-only access to the WLC's Monitor tab - without it, ISE has no instruction to pass that privilege to the WLC. Second, an identity group must be configured (Choice C) so that helpdesk user accounts can be grouped together and targeted by the authorization policy. Choice A is wrong because an 'authentication profile' is not a standard ISE construct in this flow - the authentication policy itself is already configured. Choice D is wrong because 'Wireless role' provides broader access, not the scoped Monitor-only access required. Choice E (TACACS command sets) controls which CLI commands a user can run on a device, which is irrelevant here since the requirement is GUI tab access, not CLI access.
Topics
Community Discussion
No community discussion yet for this question.