Practice SISE Policy Enforcement questions with full explanations on every answer.
Start practicing
Policy Enforcement — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which THREE components are required to successfully deploy a Scalable Group Access (SGA) policy for SGT enforcement?
2When configuring a RADIUS authorization policy for a dot1x deployment, which TWO attributes are commonly used to assign a dynamic VLAN?
3When configuring dACLs for enforcement on Cisco IOS switches, which TWO of the following are true regarding the behavior of the dACL downloaded from Cisco ISE?
4You are implementing Cisco TrustSec and need to restrict traffic between two different SGTs on a Cisco Catalyst switch. Which policy component enforces this communication restriction?
5An administrator needs to implement SGT-based access control where SGT 10 (Finance) cannot communicate with SGT 20 (HR). What is the mandatory prerequisite on the ISE policy side?
6You are configuring a policy set in Cisco ISE for wireless clients. You need to ensure that the policy set only applies to requests originating from a specific WLC. Which condition should you use?
7A network administrator needs to ensure that wired 802.1X devices are assigned a specific VLAN based on their AD group membership. Which component in the ISE Policy Set should be configured to map the AD group to a specific VLAN assignment?
8You are configuring a policy set for wireless guest access and need to ensure that the authorization policy only triggers if the user has successfully authenticated via the Guest portal. Which condition should you use?
9Which component in ISE defines the 'result' of an authorization rule?
10Which attribute is used to enforce dACLs on a Cisco Catalyst switch from ISE?
11When configuring a dACL for a guest user, what is the mandatory format for the access control list entries?
12You have multiple Policy Sets. When ISE evaluates incoming RADIUS requests, which mechanism determines which Policy Set is matched?
13A user is authenticating using EAP-TLS. Where is the certificate validation policy configured in ISE?
14A TACACS+ command authorization policy is failing to restrict specific configuration changes on a Cisco IOS device. Which field in the TACACS+ Profile must be correctly configured to ensure the command list is evaluated?
15A customer needs to block access to a specific server subnet for all employees except the IT department. Which method is most scalable using Cisco TrustSec?
16When troubleshooting a failed authorization, which ISE live log column identifies the specific rule that was matched?
17What is the function of the 'Default' policy set in ISE?
18Which of the following is a valid condition for an ISE Authorization Policy?
19In an ISE Authorization Policy, what happens if no rules match a request?
20You want to implement a 'Change of Authorization' (CoA) after a user changes their location. How is the CoA triggered by ISE?
21Which option in an Authorization Profile allows you to specify a URL for a WebAuth redirect?
22A user is assigned an SGT, but the switch does not apply the correct filtering. What is the most likely reason for the SGACL enforcement failure?
23When using TACACS+ for device administration, what role does the 'Shell Profile' play?
24You are configuring a policy to block access for non-compliant devices. Where do you configure the posture status as a policy condition?
25Which of the following is NOT a standard RADIUS attribute type used in ISE?
26You need to ensure that only specific MAC OUI addresses are allowed to connect via MAB. Where do you configure this restriction?
27During an 802.1X process, the NAD sends an Access-Request with a specific Calling-Station-ID. If ISE does not find this in its Endpoint DB, what is the default behavior for the 'Unknown' status?
28A user is authenticated, but their authorization profile returns the wrong VLAN. Which troubleshooting tool in ISE is best suited to verify the attributes sent to the NAD?
29What is the primary benefit of using a Policy Set compared to the legacy 'Rule-Based' approach in ISE?
30You are implementing 'Device Administration' (TACACS+) and want to restrict an admin to 'show' commands only. How do you construct this policy?
31In the ISE Policy Set, which component is used to define the user credentials' verification method?
32When a device connects to a port, it is put into 'Monitoring Mode'. What is the purpose of this state?
33Which of the following is a key requirement for dACL enforcement on a Cisco switch?
34Which ISE menu path is used to create a new Authorization Profile?
35You are troubleshooting SGT propagation. If an SGT is not being embedded in the SXP protocol, what should you verify?
36Which of the following is an example of an 'Exception' policy in ISE?
37What does the 'Fallthrough' option in an ISE Policy Set rule do?
38You need to apply a dACL that denies all traffic to a specific server subnet (10.1.1.0/24) while permitting everything else. What is the correct syntax for the last line of the dACL?
39Which TWO of the following are valid components of an ISE Authorization Policy rule?
40When configuring a policy set, which attribute is most commonly used to distinguish between a Wired and Wireless request?
41What is the purpose of an Authorization Profile's 'Common Tasks'?
42You have a Cisco switch that supports both RADIUS and TACACS+. When using ISE for device administration, which protocol is mandatory for command-level authorization?
43Which TWO of the following are valid ways to assign a VLAN in an ISE Authorization Profile?
44Which THREE of the following items can be included in an ISE 'Common Task' for authorization?
45Which TWO of the following are benefits of using the Cisco TrustSec architecture?
46Which TWO of the following are valid locations to check for policy match results in ISE?
47Which THREE of the following are required to successfully implement SXP (SGT Exchange Protocol)?
48Which TWO of the following authentication protocols are supported by ISE for 802.1X?
49Which THREE of the following are valid Policy Set conditions?
50Which THREE of the following are steps required to configure Cisco ISE for TACACS+ command authorization?
51Which THREE of the following are necessary to configure CWA (Centralized Web Authentication)?
52Which THREE of the following are components of a Cisco TrustSec 'Security Group' policy enforcement?
53Which TWO of the following are valid ways to restrict access based on posture status in ISE?
54Which TWO of the following are types of Identity Sources in ISE?
55Which THREE of the following are found in an Authorization Profile's 'Advanced Attributes'?
56Which TWO of the following are steps to handle a user authentication failure in ISE?
57An administrator wants to apply a dACL to a user session. Which Cisco ISE component must be configured to ensure the dACL is correctly pushed to the network access device?
58You are configuring a policy set for wireless clients and need to ensure that only devices matching a specific internal endpoint group are granted access. Where should you define this requirement in the Cisco ISE policy set?
59Which Cisco ISE construct is used to combine authentication and authorization policies into a single logical container?
60Which option in the Cisco ISE Authorization Policy allows you to set a specific VLAN for a wireless client?
61A user is failing to receive the expected dACL. The ISE logs show the correct authorization rule was matched, but the dACL is not applied. What is the most likely cause?
62When configuring a TACACS+ command authorization policy for network device management, where do you define which specific commands a user is allowed to execute?
63You need to ensure that different network devices trigger different authorization policies based on their location. What is the best way to group these devices for policy conditions?
64You are troubleshooting a scenario where an SGT is not being assigned to a session. You notice the Authorization Profile is correctly configured. What must be configured on the Network Access Device (NAD) to allow the SGT to be learned from the RADIUS Access-Accept?
65When creating a Policy Condition in Cisco ISE, which attribute is most commonly used to identify a user's location?
66A guest user is failing authentication because they are hitting the wrong policy set. How can you ensure the guest traffic is matched to the 'Guest' policy set?
67You have a policy set where authentication succeeds, but the user is hitting the 'Default' authorization rule instead of the expected rule. What should you check first?
68Which THREE of the following are valid components of a RADIUS-based Authorization Policy rule in Cisco ISE?
69When using TACACS+ for device administration, which result object is used to define the privilege level of the user?
70Which TWO of the following steps are required to implement SGT-based enforcement using an SXP connection?
71Which THREE attributes can be used within a Cisco ISE Authorization Policy condition?
72Which TWO settings in an Authorization Profile are commonly used to restrict a client's network access?
73Which THREE items are required when configuring a new Policy Set in Cisco ISE?
74Which TWO of the following are true regarding the order of operations in Cisco ISE policy evaluation?
The Policy Enforcement domain covers the key concepts tested in this area of the SISE exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SISE domains — no account required.
The Courseiva SISE question bank contains 74 questions in the Policy Enforcement domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Policy Enforcement domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included