300-715 · Question #419
An engineer must deploy device administration using Cisco ISE. Each department requires its own groups and privileges within Cisco ISE, and some departments only need access to specific devices. The…
The correct answer is C. TACACS authentication settings. Device administration in Cisco ISE uses the TACACS+ protocol, not RADIUS. TACACS+ is specifically designed for controlling administrator access to network devices (CLI login, command authorization, accounting). After enabling the device administration service in ISE and…
Question
An engineer must deploy device administration using Cisco ISE. Each department requires its own groups and privileges within Cisco ISE, and some departments only need access to specific devices. The engineer enables the device administration service and creates user identity groups. What must the engineer configure next on the network devices?
Options
- ASNMP settings
- Badvanced TrustSec settings
- CTACACS authentication settings
- DRADIUS authentication settings
How the community answered
(31 responses)- A6% (2)
- B3% (1)
- C87% (27)
- D3% (1)
Explanation
Device administration in Cisco ISE uses the TACACS+ protocol, not RADIUS. TACACS+ is specifically designed for controlling administrator access to network devices (CLI login, command authorization, accounting). After enabling the device administration service in ISE and creating user identity groups, the next required step is to configure TACACS+ authentication settings on the network devices - pointing them to the ISE server as the TACACS+ server. RADIUS (D) is used for network access control (802.1X, MAB, VPN), not device administration. SNMP (A) is a monitoring/management protocol unrelated to AAA. TrustSec (B) is for Security Group Tag-based segmentation and is separate from device administration.
Topics
Community Discussion
No community discussion yet for this question.