Courseiva

SISE · domain

Network Access Device Administration

Practise Cisco Implementing and Configuring Cisco Identity Services Engine (SISE, 300-715, CCNP Security) (SISE) Network Access Device Administration practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

47 questions8 easy23 medium16 hard

Focused practice

Practice Network Access Device Administration questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Network Access Device Administration

Network Access Device Administration questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Access Device Administration exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Network Access Device Administration questions (47)

Click any question to see the full explanation, or start a practice session above.

1

When defining a Shell Profile for a TACACS+ administrator, which setting ensures the user is placed into privilege level 15 immediately upon login?

Medium
2

Which THREE of the following are reasons why a TACACS+ authorization request might fail? (Choose three)

Hard
3

Which attribute in a Shell Profile is used to control whether a user can perform 'enable' commands?

Medium
4

You are implementing TACACS+ device administration for a group of routers. You need to assign specific privilege levels to different users. Where in the ISE policy set is this privilege assignment configured?

Medium
5

Which TWO of the following are true regarding the configuration of Command Sets in Cisco ISE?

Medium
6

Which TWO of the following are valid ways to define conditions in a TACACS+ Policy Set? (Choose two)

Medium
7

A network administrator needs to restrict access so that engineers can only run 'show' commands on core switches via TACACS+. How should the Command Set be configured?

Medium
8

You are troubleshooting a scenario where an admin cannot execute a specific command despite the Command Set having 'Permit' for that command. What is a common reason?

Hard
9

You need to ensure that TACACS+ authentication requests for network devices are only accepted if the device IP matches a specific Network Device Group. Where do you configure the Device Type condition?

Hard
10

Which port does Cisco ISE use by default for TACACS+ communication with network devices?

Easy
11

In the context of TACACS+, what is the purpose of the 'Network Device Group'?

Easy
12

When troubleshooting TACACS+ authentication issues in Cisco ISE, which log file should you monitor to see the specific request details and the policy match result?

Hard
13

Which TWO of the following are valid components of a TACACS+ Authorization Policy in Cisco ISE? (Choose two)

Medium
14

Which of the following is a best practice when configuring TACACS+ for network administration?

Medium
15

Where are the TACACS+ accounting logs stored and viewed in the ISE management console?

Medium
16

You are troubleshooting a TACACS+ issue where a user can log in but cannot execute any commands. The policy set hits the correct rule. What is the most likely reason?

Hard
17

A user is assigned a Command Set that permits all commands, but they are still receiving 'Access Denied' when running 'reload'. What is the most likely reason?

Hard
18

Which component in Cisco ISE defines the TACACS+ privilege levels and attributes sent to the network device?

Medium
19

Which TWO of the following are benefits of using Network Device Groups (NDG)? (Choose two)

Medium
20

Which component in ISE is responsible for mapping an authenticated user to a specific set of permissions and command restrictions in a TACACS+ environment?

Easy
21

Which THREE of the following items are considered 'results' in an ISE authorization policy? (Choose three)

Hard
22

How can you verify that ISE is receiving TACACS+ requests from a specific switch?

Medium
23

You are configuring a policy to allow 'Read-Only' access for junior admins. You have created a Command Set that allows 'show' commands. What else is required to implement 'Read-Only' access correctly?

Hard
24

Which THREE of the following are characteristics of the TACACS+ protocol? (Choose three)

Hard
25

What is the benefit of using multiple TACACS+ Policy Sets?

Easy
26

If a user is authenticated via TACACS+ but no authorization policy matches, what is the default behavior?

Hard
27

Which TWO methods can be used to verify that a TACACS+ request from a network device is reaching the Cisco ISE PSN?

Hard
28

Which menu path in Cisco ISE is used to define a new Network Device Group?

Easy
29

Which TWO of the following are true regarding TACACS+ command sets? (Choose two)

Medium
30

You are configuring a Network Device Group in Cisco ISE to organize devices by geographical location. Which menu path should you navigate to in order to create a new Network Device Group?

Easy
31

An administrator notices that TACACS+ authentication is failing for devices. The logs show 'RADIUS request received'. What is the most likely cause?

Hard
32

When configuring a Shell Profile, what is the purpose of the 'Common Tasks' section?

Medium
33

Which THREE of the following are valid actions when configuring a Command Set for a user? (Choose three)

Hard
34

If a user is assigned a Shell Profile with a specific 'Auto-Command' configured, what happens when they log into the network device?

Medium
35

Which statement best describes the role of the TACACS+ 'Accounting' feature?

Medium
36

You need to allow users to run commands that start with 'show' but deny any 'show' commands that contain 'password'. How should the Command Set be configured?

Hard
37

Which THREE items are configurable within a TACACS+ Shell Profile in Cisco ISE?

Hard
38

You are configuring a TACACS+ command set to restrict an administrator from running 'show running-config' on Cisco switches. Which match condition ensures that this specific command is blocked while allowing other 'show' commands?

Medium
39

Which TWO of the following are true about Shell Profiles? (Choose two)

Medium
40

How does Cisco ISE handle requests that do not match any configured TACACS+ Authorization Policy?

Medium
41

What is the maximum number of TACACS+ servers you can configure on a Cisco device for redundancy?

Easy
42

You want to use TACACS+ for administrative access. Which protocol feature distinguishes TACACS+ from RADIUS for device administration?

Medium
43

What is the primary function of the TACACS+ 'Shared Secret' configured on both the Cisco ISE and the Network Access Device?

Easy
44

When configuring a Shell Profile for TACACS+, which of the following attributes can be controlled to limit how long a session stays active without input?

Medium
45

A network engineer reports that they can log into a switch via TACACS+, but cannot run any commands. What is the most likely cause?

Medium
46

When adding a network device to ISE, you select the 'TACACS+ Authentication Settings' checkbox. What is the impact of this action?

Medium
47

When setting up TACACS+ for network administration, which THREE configurations must be present on the Cisco network device? (Choose three)

Hard

Frequently asked questions

What does the Network Access Device Administration domain cover on the SISE exam?
Network Access Device Administration questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 47 Network Access Device Administration questions in the SISE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Access Device Administration questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-sise CISCO-SISE network access device administration Practice Questions