Question 111

An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+ However, the administrator must restrict certain commands based on one of three user roles that require different commands How is this accomplished without creating too many objects using Cisco ISE?
  • Question 112

    Wireless network users authenticate to Cisco ISE using 802.1X through a Cisco Catalyst switch.
    An engineer must create an updated configuration to assign a security group tag to the user's traffic using inline tagging to prevent unauthenticated users from accessing a restricted server.
    The configurations were performed:
    - configured Cisco ISE as a Cisco TrustSec AAA server
    - configured the switch as a RADIUS device in Cisco ISE
    - configured the wireless LAN controller as a TrustSec device in Cisco
    ISE
    - created a security group tag for the wireless users
    - created a certificate authentication profile
    - created an identity source sequence
    - assigned an appropriate security group tag to the wireless users
    - defined security group access control lists to specify an egress
    policy
    - enforced the access control lists on the TrustSec policy matrix in
    Cisco ISE
    - configured TrustSec on the switch
    - configured TrustSec on the wireless LAN controller
    Which two actions must be taken to complete the configuration? (Choose two.)
  • Question 113

    A network administrator has just added a front desk receptionist account to the Cisco ISE Guest Service sponsor group. Using the Cisco ISE Guest Sponsor Portal, which guest services can the receptionist provide?
  • Question 114

    An engineer is designing a BYOD environment utilizing Cisco ISE for devices that do not support native supplicants Which portal must the security engineer configure to accomplish this task?
  • Question 115

    Which Cisco ISE feature enables administrators to enroll a certificate to an endpoint with MAC address 04:90:45:06:46:AA without the need for an external PKI?