Q11Network Access Device AdministrationMultiple answers
Which two actions take place when a device administrator logs in to a device through a Cisco ISE server? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 20
A, E 8
Selected Answer: AE
The answer is A & E.
It is not C, because the question uses the words 'logs in' and option C uses the term authorization. Logging in is Authentication, not Authorization
5
Could be A,C and E. The device queries ISE, and ISE can use an internal or external identity store.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A
The device administrator performs the task of setting up a device to communicate with the Cisco ISE server. When a device administrator logs on to a device, the device queries the Cisco ISE server, which in turn queries an internal or external identity store, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes.
3
I think the correct ones are A and E
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A
3
The correct answer is A and E.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_device_admin.html#concept_9B1DD5A7AD9C445AAC764722E6E7D32A
2
CORRECT ANSWER IS C & E
READ THE MANUALS
When a device administrator logs on to a device, the device queries the Cisco ISE server, which in turn queries an internal or external identity store, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes.
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html
2
In your case, to achieve a device login with ISE, we use internal user DB, so the answers should be A & C, the device queries the ISE and the ISE queries the internal database
A, E 2
Selected Answer: AE
"Cisco ISE server device administrator" makes me think it's an ISE admin. An ISE admin can use internal or external credentials.
A, E 2
Selected Answer: AE
Can be either internal or external
2
Bro, this question doesn't make any sense at all.
2
Typical tricky question. A,C,E all look correct but authorization comes only after successful authentication so I would choose A, E as the correct answers.
A, E 2
Selected Answer: AE
I'm going with A& E. there is an internal ISE admin database and it can use an external Identity source such as AD. but the key in the question is asking about an ISE admin logging into ISE- not sure what they mean by "device"; if they are talking NAD then it would be Tacacs+
2
Correct are A, E.
C is not correct, because the question is about authentication, not authorization (that comes later).
2
A "Device" never ever queries an identity store directly. That rules out two of them. ISE is the only thing that queries an ID Store and in this case, Device Access is only internal database. This IS About TACACS because it is talking about Device Administrators. With those things in mind it gets easier to pick which options are viable. Take a quick look at the vendor docs which say the same thing.
2
The answer is A&E. It is the authentication server's(ISE) role.
1
For sure A & E are the strongest answers
A, C 1
Selected Answer: AC
Does "Cisco ISE server device administrator" mean the internal identity store?
1
So A, C and E according to your answer.
1
For me the answer is C and E
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html#:~:text=The%20device%20administrator%20performs%20the,details%20of%20the%20device%20administrator.
the admin logs into the switch and after that the switch has radius or tacacs, after that you have configured a policy in ISE, usually for network access what you do is connect an AD to ISE so that Cisco ISE can query an external identity and validate the user that the admin is actually using for authetication
1
ok.... this question is really tricky and cringe... after reading that C is about authorization... so.... because this is an authentication session i think that Cisco is thinking about what ISE can do when a user logs into a device?
The device of course has tacacs or radius or both configured, and what ISE can do is either look for an internal or an external identity store so A and E at the end....
1
I think A & E are correct.
“The device administrator performs the task of setting up a device to communicate with the Cisco ISE server. When a device administrator logs on to a device, the device queries the Cisco ISE server (NOTE: queries ISE server, NOT INTERNAL OR EXTERNAL IDENTITY STORE), which in turn queries an INTERNAL or EXTERNAL IDENTITY STORE, to validate the details of the device administrator. When the validation is done by the Cisco ISE server, the device informs the Cisco ISE server of the final outcome of each session or command authorization operation for accounting and auditing purposes.”
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html