ETExamTower
Q38Policy Enforcement

An administrator must provide users with the same level of access to network devices when they log in using TACACS+. However, the administrator must limit certain commands according to one of three user roles, each requiring different commands. How can this be achieved without creating too many objects in Cisco ISE?

← → navigate · a answer
Community votes
D
100% (3)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 4
D 10
Selected Answer: D it should be one shell profile for all NADs at the same level ... and one command set for the one who needs restricted commands if the others do not need a command set (blank in policy set page) or multiple command sets if the other two rules need the command set to be set.. so the answer is ; A or D . and D is the closest correct answer
D 3
Selected Answer: D C and D are both good Answer, but D is better because of the last sentence in the question "without creating too many objects using Cisco ISE", it is right that could be worst to configure one shell profile and multiple command set because is not scalable, if you have a lot of users it might become cumbersome but if you udon't want to create many object then the best answer is D, even if in a REAL big environment the best One would be C.
3
D makes sense. We are going to create the same shell profile, the shell profile is where you assign the level of privilage returned to the NAD device for that user. What we can do is set a specific command set to have more control over administrator users.
1
We have three user roles (three means multiple). I think C is correct. Because each user's role should have its shell profile.