SISE · domain
Network Access Device Administration
Practise Cisco Implementing and Configuring Cisco Identity Services Engine (SISE, 300-715, CCNP Security) (SISE) Network Access Device Administration practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Network Access Device Administration questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Network Access Device Administration
Network Access Device Administration questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Network Access Device Administration exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Network Access Device Administration questions (47)
Click any question to see the full explanation, or start a practice session above.
When defining a Shell Profile for a TACACS+ administrator, which setting ensures the user is placed into privilege level 15 immediately upon login?
Medium2Which THREE of the following are reasons why a TACACS+ authorization request might fail? (Choose three)
Hard3Which attribute in a Shell Profile is used to control whether a user can perform 'enable' commands?
Medium4You are implementing TACACS+ device administration for a group of routers. You need to assign specific privilege levels to different users. Where in the ISE policy set is this privilege assignment configured?
Medium5Which TWO of the following are true regarding the configuration of Command Sets in Cisco ISE?
Medium6Which TWO of the following are valid ways to define conditions in a TACACS+ Policy Set? (Choose two)
Medium7A network administrator needs to restrict access so that engineers can only run 'show' commands on core switches via TACACS+. How should the Command Set be configured?
Medium8You are troubleshooting a scenario where an admin cannot execute a specific command despite the Command Set having 'Permit' for that command. What is a common reason?
Hard9You need to ensure that TACACS+ authentication requests for network devices are only accepted if the device IP matches a specific Network Device Group. Where do you configure the Device Type condition?
Hard10Which port does Cisco ISE use by default for TACACS+ communication with network devices?
Easy11In the context of TACACS+, what is the purpose of the 'Network Device Group'?
Easy12When troubleshooting TACACS+ authentication issues in Cisco ISE, which log file should you monitor to see the specific request details and the policy match result?
Hard13Which TWO of the following are valid components of a TACACS+ Authorization Policy in Cisco ISE? (Choose two)
Medium14Which of the following is a best practice when configuring TACACS+ for network administration?
Medium15Where are the TACACS+ accounting logs stored and viewed in the ISE management console?
Medium16You are troubleshooting a TACACS+ issue where a user can log in but cannot execute any commands. The policy set hits the correct rule. What is the most likely reason?
Hard17A user is assigned a Command Set that permits all commands, but they are still receiving 'Access Denied' when running 'reload'. What is the most likely reason?
Hard18Which component in Cisco ISE defines the TACACS+ privilege levels and attributes sent to the network device?
Medium19Which TWO of the following are benefits of using Network Device Groups (NDG)? (Choose two)
Medium20Which component in ISE is responsible for mapping an authenticated user to a specific set of permissions and command restrictions in a TACACS+ environment?
Easy21Which THREE of the following items are considered 'results' in an ISE authorization policy? (Choose three)
Hard22How can you verify that ISE is receiving TACACS+ requests from a specific switch?
Medium23You are configuring a policy to allow 'Read-Only' access for junior admins. You have created a Command Set that allows 'show' commands. What else is required to implement 'Read-Only' access correctly?
Hard24Which THREE of the following are characteristics of the TACACS+ protocol? (Choose three)
Hard25What is the benefit of using multiple TACACS+ Policy Sets?
Easy26If a user is authenticated via TACACS+ but no authorization policy matches, what is the default behavior?
Hard27Which TWO methods can be used to verify that a TACACS+ request from a network device is reaching the Cisco ISE PSN?
Hard28Which menu path in Cisco ISE is used to define a new Network Device Group?
Easy29Which TWO of the following are true regarding TACACS+ command sets? (Choose two)
Medium30You are configuring a Network Device Group in Cisco ISE to organize devices by geographical location. Which menu path should you navigate to in order to create a new Network Device Group?
Easy31An administrator notices that TACACS+ authentication is failing for devices. The logs show 'RADIUS request received'. What is the most likely cause?
Hard32When configuring a Shell Profile, what is the purpose of the 'Common Tasks' section?
Medium33Which THREE of the following are valid actions when configuring a Command Set for a user? (Choose three)
Hard34If a user is assigned a Shell Profile with a specific 'Auto-Command' configured, what happens when they log into the network device?
Medium35Which statement best describes the role of the TACACS+ 'Accounting' feature?
Medium36You need to allow users to run commands that start with 'show' but deny any 'show' commands that contain 'password'. How should the Command Set be configured?
Hard37Which THREE items are configurable within a TACACS+ Shell Profile in Cisco ISE?
Hard38You are configuring a TACACS+ command set to restrict an administrator from running 'show running-config' on Cisco switches. Which match condition ensures that this specific command is blocked while allowing other 'show' commands?
Medium39Which TWO of the following are true about Shell Profiles? (Choose two)
Medium40How does Cisco ISE handle requests that do not match any configured TACACS+ Authorization Policy?
Medium41What is the maximum number of TACACS+ servers you can configure on a Cisco device for redundancy?
Easy42You want to use TACACS+ for administrative access. Which protocol feature distinguishes TACACS+ from RADIUS for device administration?
Medium43What is the primary function of the TACACS+ 'Shared Secret' configured on both the Cisco ISE and the Network Access Device?
Easy44When configuring a Shell Profile for TACACS+, which of the following attributes can be controlled to limit how long a session stays active without input?
Medium45A network engineer reports that they can log into a switch via TACACS+, but cannot run any commands. What is the most likely cause?
Medium46When adding a network device to ISE, you select the 'TACACS+ Authentication Settings' checkbox. What is the impact of this action?
Medium47When setting up TACACS+ for network administration, which THREE configurations must be present on the Cisco network device? (Choose three)
HardOther domains
All SISE exam domains
Frequently asked questions
- What does the Network Access Device Administration domain cover on the SISE exam?
- Network Access Device Administration questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 47 Network Access Device Administration questions in the SISE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Network Access Device Administration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.