Cisco · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which menu path in Cisco ISE is used to define a new Network Device Group?
Operations > TACACS Livelogs
Administration > Identity Management
Policy > Policy Elements > Results
Administration > Network Resources > Network Device Groups
This is the correct navigation path.
What is the primary function of the TACACS+ 'Shared Secret' configured on both the Cisco ISE and the Network Access Device?
To authenticate the TACACS+ packet exchange
The secret validates the integrity and authenticity of the communication.
To assign the device to a specific group
To encrypt the entire packet header
To enable SSL/TLS encryption for the session
You need to ensure that TACACS+ authentication requests for network devices are only accepted if the device IP matches a specific Network Device Group. Where do you configure the Device Type condition?
In the Command Set definition
In the TACACS+ Profile settings
In the Policy Set condition using 'Device Type'
Conditions based on NDG (Device Type) are evaluated at the policy set or policy rule level.
In the Global System Settings
A network engineer reports that they can log into a switch via TACACS+, but cannot run any commands. What is the most likely cause?
The Command Set is missing or not assigned in the Authorization Policy
Authorization failed for the command execution phase.
The switch is not configured for 'aaa authorization commands'
The shell profile lacks privilege level configuration
The user is not in the correct Identity Store
You want to use TACACS+ for administrative access. Which protocol feature distinguishes TACACS+ from RADIUS for device administration?
RADIUS allows command-level authorization
TACACS+ encrypts the entire packet body
TACACS+ encrypts the entire payload, whereas RADIUS only encrypts the password.
TACACS+ is an open standard protocol
TACACS+ uses UDP port 49
When defining a Shell Profile for a TACACS+ administrator, which setting ensures the user is placed into privilege level 15 immediately upon login?
Set 'Attribute' to 'priv-lvl=15' in custom attributes
Set the 'Auto-Command' to 'enable 15'
Configure the 'Privilege Level' field to 15
The Default Privilege attribute sets the initial level.
Enable 'Maximum Privilege' in the command set
Want more Network Access Device Administration practice?
Practice this domainWhen configuring certificate-based BYOD onboarding, you notice that devices are successfully registered, but the client certificate issuance fails. Where should you examine the logs to troubleshoot the Certificate Authority (CA) interaction?
Policy > Policy Elements > Results > Certificate Templates
Operations > RADIUS Livelog
Operations > Reports > Endpoints and Users > Certificate Provisioning
This report specifically tracks certificate enrollment attempts and failures.
Administration > System > Certificates > Certificate Signing Requests
A user reports that their BYOD device is not being recognized as 'Compliant' even though the MDM shows it is compliant. Which ISE component is responsible for retrieving this status?
The ISE MDM Server connector
The connector is the bridge that retrieves status updates from the MDM.
The ISE Policy Information Point (PIP)
The ISE Monitoring node
The ISE RADIUS service
When configuring an Authorization Policy for BYOD, which condition should be used to ensure the device has successfully performed BYOD registration?
Session:BYODRegistrationStatus EQUALS Registered
This attribute is set by ISE once the registration and provisioning flow completes.
Endpoint:Profile EQUALS RegisteredDevice
Session:RegistrationMode EQUALS Auto
Device:AccessType EQUALS BYOD
What is the purpose of the 'Network Setup Assistant' (NSA) in the context of Cisco ISE BYOD?
To provide a VPN tunnel to the internal network
To manage the user's Active Directory account
To scan the device for malware before allowing network access
To configure the native supplicant settings for secure network access
The NSA automates the configuration of WiFi profiles and certificate installation.
During BYOD onboarding, the client is unable to download the Network Setup Assistant (NSA). You verify the portal settings and observe that the 'Client Provisioning' resource is correctly assigned to the policy. What is the most likely cause if the device fails to reach the download page?
The user is not part of the Active Directory group assigned to the policy
The client does not have the native supplicant installed
The redirect ACL is blocking traffic to the ISE IP address on TCP port 8443
If the ACL blocks the traffic, the client cannot communicate with the ISE provisioning service.
The certificate on the ISE portal is expired
You are integrating an MDM server with ISE for BYOD. The requirement is that ISE must check the compliance status of the device before granting full network access. Which feature must be enabled in the MDM configuration within ISE?
Configure a 'Compliance' RADIUS attribute
Enable 'Device Compliance' in the MDM server configuration object
This setting allows ISE to query the MDM for the compliance status of the registered device.
Enable 'Allow full access' in the Authorization Policy
Enable 'MDM Enrollment' in the Policy Set
Want more BYOD practice?
Practice this domainA user is unable to pass posture assessment because the 'AnyConnect Compliance Module' is not detecting the antivirus software. Which log file on the endpoint should be reviewed to troubleshoot the compliance module's scanning logic?
NAC Agent Log (nac_agent.log)
Windows Event Viewer - Application Log
AnyConnect Compliance Module log (ac_ise_posture.log)
This is the primary log file on the Windows endpoint for troubleshooting compliance agent scan results.
ISE Posture Log (ise_posture.log)
What is the primary function of the 'Monitor Mode' in Cisco ISE Posture policies?
To gather compliance data without restricting network access
Monitor Mode is explicitly for visibility without enforcement.
To automatically remediate endpoints
To bypass the posture check entirely
To block all traffic until the agent is installed
When configuring an AnyConnect Posture Policy, which option allows the administrator to force the agent to perform a scan regardless of the current posture status?
Posture Type set to 'Continuos'
Agent Enforcement set to 'Mandatory'
Mandatory enforcement forces the agent to report and remediate compliance.
Policy Status set to 'Production'
Periodic Scanning enabled in Client Provisioning Policy
Wait, the question asks for the Posture Requirement setting specifically. 'Mandatory' is the correct policy enforcement setting.
Which protocol is used by the AnyConnect agent to communicate posture information to the ISE Policy Service Node (PSN)?
RADIUS
HTTP/HTTPS (TCP 8905)
The Cisco ISE posture agent communicates with the PSN over TCP port 8905.
DNS
SNMP
Where do you upload the AnyConnect posture agent packages to make them available for Client Provisioning?
Operations > Troubleshoot > Client Provisioning
Policy > Policy Elements > Results > Client Provisioning > Resources
This is the designated location for uploading agent binaries.
Policy > Posture > Policy
Administration > System > Settings > Posture
You are configuring a posture policy for Windows endpoints. Which component must be configured to provide users with a link to download the required compliance software if the posture check fails?
Post-Posture Authorization Rule
Client Provisioning Policy
File Remediation Action
File Remediation is specifically designed to provide a download link or location for remediation software.
Posture Requirement
Want more Endpoint Compliance practice?
Practice this domainWhen configuring an LWA portal, you notice that the HTTP traffic is not being redirected. What is a primary requirement for LWA that differs from CWA?
The NAD must have the 'ip http server' enabled.
LWA requires the local switch web server to intercept HTTP requests.
The endpoint must be statically assigned an IP.
A redirect ACL must be applied to the ISE interface.
The ISE node must be the default gateway.
Which component is responsible for the actual redirection of the guest user's browser in a CWA flow?
The Cisco ISE Policy Service Node (PSN)
The Network Access Device (NAD)
The switch intercepts the traffic and returns a 302 redirect.
The endpoint's default browser
The Guest Portal application
A guest user reports they receive a certificate warning when redirected to the ISE Guest portal. What is the most common cause of this issue?
The ISE portal is configured for HTTP instead of HTTPS.
The DNS server is not resolving the ISE FQDN.
The ISE server certificate is self-signed or not trusted by the client device.
Browsers require trusted certificates for secure connections.
The switch is not configured for SSL interception.
You are implementing a Guest flow that requires the user to accept an Acceptable Use Policy (AUP). Where is the AUP text configured within the Cisco ISE portal settings?
Policy > Policy Elements > Results > Authorization Profiles
Work Centers > Guest Access > Settings > AUP
Guest Access > Configure > Guest Portals > [Portal Name] > Portal Page Customization
This is the correct path for customizing portal pages.
Administration > System > Settings > Guest
In a CWA scenario, the user is redirected to the portal, authenticates, but the session is not transitioning from the 'redirected' state to the 'authenticated' state. What is the most likely cause?
The NAD is missing the 'aaa server radius dynamic-author' configuration.
CoA requires this configuration on the switch to listen for ISE's re-authentication request.
The Guest user group is missing from the Policy Set.
The Redirect ACL is applied to the wrong interface.
The portal URL is incorrect.
You are troubleshooting a Guest flow where the client hits the portal but cannot authenticate. You notice the MAC address is not being cached properly. Which setting in the Guest Portal configuration is responsible for enabling MAC caching?
Enable Auto-Login
Enable Guest Flow Bypass
Enable MAC Caching
This is the specific setting to enable the feature.
Enable Device Registration
Want more Web Auth And Guest Services practice?
Practice this domainYou want to improve profiling accuracy for endpoints that do not send DHCP options. You decide to use SNMP Trap profiling. What is a critical prerequisite for this to function?
The network device must be configured to send SNMP traps to the ISE PSN IP address.
Without the destination set on the switch, the ISE node will never receive the traps.
The endpoint must support SNMP agents.
The ISE node must have the SNMP Query probe enabled.
RADIUS Accounting must be disabled.
Which probe is most effective for identifying the specific operating system and browser type of an endpoint connecting via a web portal?
HTTP probe
HTTP probe extracts the User-Agent header from HTTP requests.
DHCP probe
MAC OUI probe
DNS probe
You are configuring a custom profiling policy and notice that the 'Certainty Factor' is too low for the device to be assigned to the correct group. What is the purpose of the Certainty Factor in ISE?
To determine the priority of the profiling policy.
To force the device to re-authenticate.
To indicate the confidence level that the device is correctly profiled.
It represents the cumulative score of matching profile conditions.
To limit the number of devices in an endpoint group.
You are troubleshooting an issue where IP phones are not being profiled. The SNMP read community string on the switch does not match the one configured in ISE. What is the expected behavior?
The endpoint will be profiled based on the MAC OUI only.
The SNMP trap probe will still work.
The SNMP Query probe will fail to collect CDP/LLDP data from the switch.
An invalid community string results in an authentication failure for SNMP requests.
ISE will automatically update the community string on the switch.
You have created a custom profiler condition that is not matching endpoints correctly. Where should you check the live authentication and profiling logs to verify if the attribute is being received by ISE?
Administration > System > Logging
Operations > RADIUS Livelogs
RADIUS Livelogs show the attributes received during the authentication process.
Policy > Profiling > Profiling Policies
Context Visibility > Endpoints
You are configuring a DHCP probe on a Cisco ISE node to identify endpoints. Which specific configuration step is required to ensure the ISE node receives DHCP traffic when the client and server are on a different subnet?
Configure a DHCP relay agent on the ISE node itself.
Enable DHCP Server mode on the Cisco ISE Profiling service.
Configure an IP helper-address on the Layer 3 device for the client VLAN pointing to the ISE node.
IP helper-address is required to forward DHCP requests to the ISE node.
Enable DHCP Snooping on the ISE node interface.
Want more Profiler practice?
Practice this domainWhich THREE components are required to successfully deploy a Scalable Group Access (SGA) policy for SGT enforcement?
TACACS+ Command Authorization
DHCP Snooping
SGACL definition
The policy governing the SGT interaction must exist.
TrustSec Matrix configuration
The matrix defines the SGACL to be applied between SGTs.
SGT mapping
Devices must be assigned an SGT.
When configuring a RADIUS authorization policy for a dot1x deployment, which TWO attributes are commonly used to assign a dynamic VLAN?
Service-Type equals Framed
Framed-IP-Address
Tunnel-Type equals VLAN
Mandatory to define the tunnel type.
Tunnel-Medium-Type equals 802
Mandatory to specify the medium type for the tunnel.
Cisco-AV-Pair
When configuring dACLs for enforcement on Cisco IOS switches, which TWO of the following are true regarding the behavior of the dACL downloaded from Cisco ISE?
The dACL replaces existing static ACLs on the interface.
The dACL is downloaded to the switch NVRAM.
The dACL is pushed to the switch using RADIUS VSA 11.
Cisco-AV-Pair 'ip:inacl#x' or dACL name is sent via RADIUS.
The dACL is applied globally to the switch interface.
The dACL is applied on a per-user-session basis.
dACLs allow unique policies per authenticated user session.
You are implementing Cisco TrustSec and need to restrict traffic between two different SGTs on a Cisco Catalyst switch. Which policy component enforces this communication restriction?
CTS Role-Based Policy
SGACL
SGACLs are the policy objects that define access control between SGTs.
SGT Mapping
dACL
An administrator needs to implement SGT-based access control where SGT 10 (Finance) cannot communicate with SGT 20 (HR). What is the mandatory prerequisite on the ISE policy side?
Manually map IP to SGT on all switches
Configure the SGACL on the client
Enable SGT propagation on the policy set
This ensures the SGT value is passed via the RADIUS attribute 217 to the network device.
Create a dACL with SGT 10
You are configuring a policy set in Cisco ISE for wireless clients. You need to ensure that the policy set only applies to requests originating from a specific WLC. Which condition should you use?
NetworkDevice:Name
NetworkDevice:Name allows matching based on the device defined in the ISE Network Devices list.
Radius:NAS-IP-Address
Radius:Called-Station-ID
Device:Model
Want more Policy Enforcement practice?
Practice this domainA customer is planning a large campus deployment with 50,000 concurrent endpoints. Which persona should be dedicated to handle the authentication load to ensure high performance?
Policy Administration Node (PAN)
Policy Service Node (PSN)
PSNs handle the authentication and authorization traffic in a distributed environment.
Standalone Node
Monitoring and Troubleshooting Node (MnT)
When configuring a load balancer for a group of PSNs, what is the best practice for handling RADIUS traffic?
SSL-offloading
Source-IP affinity (persistence)
Source-IP affinity ensures the RADIUS state is maintained by the same PSN.
Active-passive failover only
Round-robin without persistence
You are configuring a new ISE node for your deployment. What is the correct sequence to join a secondary node to the existing deployment?
Initiate registration from the Primary PAN under Administration > System > Deployment
This is the correct navigation path for adding nodes to an ISE deployment.
Configure the Secondary node as an standalone node and merge databases
Run the join command from the secondary node's CLI
Create a cluster via the ISE CLI setup wizard
In a high-availability deployment, you have a Primary PAN/MnT and a Secondary PAN/MnT. If the Primary PAN fails, what is the impact on the Monitoring (MnT) services?
Monitoring data remains logged to the Secondary MnT node
In a distributed deployment, the secondary node continues to collect and process logs.
The Secondary PAN must be manually promoted to Primary to restore MnT functionality
ISE enters a read-only state for all PSNs
MnT services immediately stop on all nodes
Which license type is required to enable advanced profiling and posture services on Cisco ISE?
ISE Premier
Device Admin License
ISE Essentials
ISE Advantage
Advantage provides advanced profiling and posture capabilities.
When designing an ISE deployment across WAN links, what is the primary recommendation regarding MnT nodes?
Distributed MnTs across all WAN sites
Always place MnT in the cloud
Disable logging for remote sites
Keep the MnT node in the same high-speed network as the PAN
MnT requires high bandwidth for synchronization and log processing.
Want more Architecture And Deployment practice?
Practice this domainThe SISE exam has 200 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 7 domains: Network Access Device Administration, BYOD, Endpoint Compliance, Web Auth And Guest Services, Profiler, Policy Enforcement, Architecture And Deployment. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco SISE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.