700-765 · Question #139
Which feature of ISE provides role-based access control and command level authorization with logging for auditing?
The correct answer is B. TACACS+Device Administration. ISE TACACS+ Device Administration is the specific feature that enables role-based access control, command-level authorization, and session logging for network device administration auditing.
Question
Which feature of ISE provides role-based access control and command level authorization with logging for auditing?
Options
- APlatform exchange grid
- BTACACS+Device Administration
- CContext-aware access
- DCentralized policy management
How the community answered
(43 responses)- B93% (40)
- C5% (2)
- D2% (1)
Why each option
ISE TACACS+ Device Administration is the specific feature that enables role-based access control, command-level authorization, and session logging for network device administration auditing.
Platform Exchange Grid (pxGrid) is a context-sharing framework that allows ISE to publish session data to third-party security products, not a device administration or command authorization feature.
TACACS+ Device Administration in ISE separates authentication, authorization, and accounting (AAA) for device management, allowing administrators to define granular command-level authorization policies per role. It logs every command executed on network devices, providing a full audit trail. This is distinct from RADIUS-based network access and is specifically designed for privileged device access control.
Context-aware access uses identity and contextual attributes (posture, location, device type) to enforce network access policies, but does not provide command-level authorization or device administration auditing.
Centralized policy management is a broad ISE capability describing its unified policy engine, not a specific feature tied to command-level authorization and TACACS+-based device administration logging.
Concept tested: ISE TACACS+ device administration and RBAC
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html
Topics
Community Discussion
No community discussion yet for this question.