Practice SISE Network Access Device Administration questions with full explanations on every answer.
Start practicing
Network Access Device Administration — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which menu path in Cisco ISE is used to define a new Network Device Group?
2What is the primary function of the TACACS+ 'Shared Secret' configured on both the Cisco ISE and the Network Access Device?
3You need to ensure that TACACS+ authentication requests for network devices are only accepted if the device IP matches a specific Network Device Group. Where do you configure the Device Type condition?
4A network engineer reports that they can log into a switch via TACACS+, but cannot run any commands. What is the most likely cause?
5You want to use TACACS+ for administrative access. Which protocol feature distinguishes TACACS+ from RADIUS for device administration?
6When defining a Shell Profile for a TACACS+ administrator, which setting ensures the user is placed into privilege level 15 immediately upon login?
7When troubleshooting TACACS+ authentication issues in Cisco ISE, which log file should you monitor to see the specific request details and the policy match result?
8You are configuring a TACACS+ command set to restrict an administrator from running 'show running-config' on Cisco switches. Which match condition ensures that this specific command is blocked while allowing other 'show' commands?
9Which port does Cisco ISE use by default for TACACS+ communication with network devices?
10If a user is assigned a Shell Profile with a specific 'Auto-Command' configured, what happens when they log into the network device?
11When adding a network device to ISE, you select the 'TACACS+ Authentication Settings' checkbox. What is the impact of this action?
12You are configuring a policy to allow 'Read-Only' access for junior admins. You have created a Command Set that allows 'show' commands. What else is required to implement 'Read-Only' access correctly?
13You are troubleshooting a scenario where an admin cannot execute a specific command despite the Command Set having 'Permit' for that command. What is a common reason?
14How does Cisco ISE handle requests that do not match any configured TACACS+ Authorization Policy?
15Which attribute in a Shell Profile is used to control whether a user can perform 'enable' commands?
16In the context of TACACS+, what is the purpose of the 'Network Device Group'?
17Where are the TACACS+ accounting logs stored and viewed in the ISE management console?
18How can you verify that ISE is receiving TACACS+ requests from a specific switch?
19What is the benefit of using multiple TACACS+ Policy Sets?
20You need to allow users to run commands that start with 'show' but deny any 'show' commands that contain 'password'. How should the Command Set be configured?
21A user is assigned a Command Set that permits all commands, but they are still receiving 'Access Denied' when running 'reload'. What is the most likely reason?
22If a user is authenticated via TACACS+ but no authorization policy matches, what is the default behavior?
23Which component in Cisco ISE defines the TACACS+ privilege levels and attributes sent to the network device?
24Which of the following is a best practice when configuring TACACS+ for network administration?
25What is the maximum number of TACACS+ servers you can configure on a Cisco device for redundancy?
26Which TWO of the following are true regarding TACACS+ command sets? (Choose two)
27Which THREE of the following are characteristics of the TACACS+ protocol? (Choose three)
28Which TWO of the following are valid ways to define conditions in a TACACS+ Policy Set? (Choose two)
29Which statement best describes the role of the TACACS+ 'Accounting' feature?
30When configuring a Shell Profile, what is the purpose of the 'Common Tasks' section?
31Which TWO of the following are valid components of a TACACS+ Authorization Policy in Cisco ISE? (Choose two)
32When setting up TACACS+ for network administration, which THREE configurations must be present on the Cisco network device? (Choose three)
33Which THREE of the following are valid actions when configuring a Command Set for a user? (Choose three)
34Which TWO of the following are true about Shell Profiles? (Choose two)
35Which TWO of the following are benefits of using Network Device Groups (NDG)? (Choose two)
36Which THREE of the following items are considered 'results' in an ISE authorization policy? (Choose three)
37Which THREE of the following are reasons why a TACACS+ authorization request might fail? (Choose three)
38You are configuring a Network Device Group in Cisco ISE to organize devices by geographical location. Which menu path should you navigate to in order to create a new Network Device Group?
39A network administrator needs to restrict access so that engineers can only run 'show' commands on core switches via TACACS+. How should the Command Set be configured?
40You are implementing TACACS+ device administration for a group of routers. You need to assign specific privilege levels to different users. Where in the ISE policy set is this privilege assignment configured?
41An administrator notices that TACACS+ authentication is failing for devices. The logs show 'RADIUS request received'. What is the most likely cause?
42You are troubleshooting a TACACS+ issue where a user can log in but cannot execute any commands. The policy set hits the correct rule. What is the most likely reason?
43When configuring a Shell Profile for TACACS+, which of the following attributes can be controlled to limit how long a session stays active without input?
44Which component in ISE is responsible for mapping an authenticated user to a specific set of permissions and command restrictions in a TACACS+ environment?
45Which TWO of the following are true regarding the configuration of Command Sets in Cisco ISE?
46Which THREE items are configurable within a TACACS+ Shell Profile in Cisco ISE?
47Which TWO methods can be used to verify that a TACACS+ request from a network device is reaching the Cisco ISE PSN?
The Network Access Device Administration domain covers the key concepts tested in this area of the SISE exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SISE domains — no account required.
The Courseiva SISE question bank contains 47 questions in the Network Access Device Administration domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network Access Device Administration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included