nerdexam
Cisco

300-715 · Question #372

An administrator must enable helpdesk users to view users' information on wireless LAN controllers in a Cisco ISE environment. The solution must meet these requirements: - Authenticate the helpdesk…

The correct answer is B. Assign the Monitor role in the TACACS profile C. Configure an identity group. To grant helpdesk users access to the Monitor tab on a WLC via TACACS+, two things are needed. First, the TACACS profile must assign the Monitor role (Choice B), because the Monitor role is what grants read-only access to the WLC's Monitor tab - without it, ISE has no…

Network Access Device Administration

Question

An administrator must enable helpdesk users to view users' information on wireless LAN controllers in a Cisco ISE environment. The solution must meet these requirements:

  • Authenticate the helpdesk users against the local ISE database.
  • Allow the helpdesk users to access the Monitor tab tor the WLC.

These configurations were performed:

  • added a wireless LAN controller
  • configured user accounts
  • enabled Device Admin Service in Cisco ISE
  • configured a TACACS profile
  • configured a policy set
  • configured an authentication policy
  • configured an authorization policy

Which two actions must be taken in Cisco ISE? (Choose two.)

Options

  • AConfigure an authentication profile
  • BAssign the Monitor role in the TACACS profile
  • CConfigure an identity group.
  • DAssign the Wireless role in the TACACS profile
  • EConfigure TACACS command sets.

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    78% (43)
  • D
    4% (2)
  • E
    13% (7)

Explanation

To grant helpdesk users access to the Monitor tab on a WLC via TACACS+, two things are needed. First, the TACACS profile must assign the Monitor role (Choice B), because the Monitor role is what grants read-only access to the WLC's Monitor tab - without it, ISE has no instruction to pass that privilege to the WLC. Second, an identity group must be configured (Choice C) so that helpdesk user accounts can be grouped together and targeted by the authorization policy. Choice A is wrong because an 'authentication profile' is not a standard ISE construct in this flow - the authentication policy itself is already configured. Choice D is wrong because 'Wireless role' provides broader access, not the scoped Monitor-only access required. Choice E (TACACS command sets) controls which CLI commands a user can run on a device, which is irrelevant here since the requirement is GUI tab access, not CLI access.

Topics

#ISE Device Admin#TACACS+ Roles#Identity Groups#WLC Access Control

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice