exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 150 discussion

Actual exam question from Cisco's 300-715
Question #: 150
Topic #: 1
[All 300-715 Questions]

An administrator is migrating device administration access to Cisco ISE from the legacy TACACS+ solution that used only privilege 1 and 15 access levels. The organization requires more granular controls of the privileges and wants to customize access levels 2-5 to correspond with different roles and access needs.
Besides defining a new shell profile in Cisco ISE, what must be done to accomplish this configuration?

  • A. Enable the privilege levels in Cisco ISE.
  • B. Enable the privilege levels in the IOS devices.
  • C. Define the command privileges for levels 2-5 in Cisco ISE.
  • D. Define the command privileges for levels 2-5 in the IOS devices.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
west33637
Highly Voted 1 year, 9 months ago
Selected Answer: C
the command privileges for 2 - 5 are defined in ISE, not on the IOS device. If the IOS device defines the command privileges, then why do we even need ISE. When ISE is centrally managing the network devices, it configures the command privileges and the shell profile.
upvoted 8 times
...
Cachaman
Most Recent 1 month, 2 weeks ago
Selected Answer: C
Correct Answer C Really poor wording, it looks like cisco hire drunk monkeys to write these questions. C. Define the Command sets for privilege levels 2-5 in Cisco ISE. D. does not make sense if you consider ISE and tacacs, the idea if to have centralized management. what if you have 1000+ devices? what if you have to remove or add a command for privilege lv 2-5?
upvoted 1 times
...
NikoTomas
8 months, 3 weeks ago
Correct is D: „Define the command privileges for levels 2-5 in the IOS devices”. --- - Privilege level under which NAD sends commands to ISE for authorization IS NOT specified by privilege level of USER but by privilege level of COMMAND - i. e. level to which particular COMMAND belongs. https://community.cisco.com/t5/network-access-control/command-authorization-by-ise/td-p/3577202 - Commands by default belongs to level 1 or 15. Question states another levels. - "When you set a command to a privilege level, all commands whose syntax is a subset of that command are also set to that level. ..." https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3se/consolidated_guide/b_consolidated_3850_3se_cg_chapter_0110010.html#ref_1352530 - We for sure need to configure IOS device privilege levels with desired commands. - Answer B: “Enable the privilege levels in the IOS devices.” - not correct, as levels are not disabled, just not configured
upvoted 2 times
NikoTomas
8 months, 3 weeks ago
- Even more, we need to configure authorization for that levels: aaa authorization commands <PRIVILEGE-LEVEL> ------ aaa authorization commands 2 default group ise aaa authorization commands 3 default group ise ... aaa authorization commands 15 default group ise
upvoted 3 times
...
...
XBfoundX
11 months, 2 weeks ago
The answer is C as west33637 is saying I have Ciso ISE so what I can do is set specific commands based the priv level Cisco ISE will give as a result, first you validate your priv level and then after that you are going to configure the specific command set that you want to use even for users that have priv 15 users
upvoted 1 times
...
IETF1
12 months ago
C. Define the command privileges for levels 2-5 in Cisco ISE.
upvoted 1 times
...
faridh
1 year, 2 months ago
Selected Answer: D
The remaining privilege levels, 2 through 14, are available for customization in individual IOS devices.
upvoted 2 times
faridh
1 year, 2 months ago
ciscopress book page 933: The remaining privilege levels, 2 through 14, are available for customization in individual IOS devices. If you were to use a customized privilege level, it would need to be configured on an IOS device first before it could be called as a TACACS+ result.
upvoted 3 times
...
...
Han2022
1 year, 2 months ago
The key point "Besides defining a new shell profile in Cisco ISE, what must be done to accomplish this configuration" Answer is B: https://learningnetwork.cisco.com/s/blogs/a0D3i000002eeWTEAY/cisco-ios-privilege-levels
upvoted 1 times
...
denverfly
1 year, 5 months ago
Selected Answer: C
The correct answer is Define the command privileges for levels 2-5 in Cisco ISE. Cisco ISE provides centralized authentication, authorization, and accounting (AAA) for network devices. The device administration service in Cisco ISE allows you to define custom privilege levels and assign commands to each level. To accomplish this configuration, you must define the command privileges for levels 2-5 in Cisco ISE.
upvoted 4 times
...
theorgin
1 year, 5 months ago
Selected Answer: D
Page 933 on Cisco Press book
upvoted 3 times
...
kornalt
1 year, 9 months ago
Selected Answer: B
After configuring the shell profiles and command sets in ISE you need to make shure that the command auhtorization needs to go via ISE by enabling the priv levels. See chapter 25 of the OCG
upvoted 1 times
kornalt
1 year, 9 months ago
also, same chapter: The remaining privilege levels, 2 through 14, are available for customization in individual IOS devices. If you were to use a customized privilege level, it would need to be configured on an IOS device first before it could be called as a TACACS+ result.
upvoted 1 times
kornalt
1 year, 9 months ago
The use case for defining a custom IOS privilege level could be to configure a customizable set of commands in order to achieve role-based access control (RBAC). However, these customizable privilege levels would have to be configured on every single network access device in order to be usable. If a command needs to be added or removed from a defined privilege level, a configuration change would be needed on each IOS device. As you can imagine, customizing privilege levels does not scale well. So D is correct
upvoted 2 times
ElCobra90
1 year, 3 months ago
I think you are wrong, question is talking about a migration, so we can suppose that privilege level and configuration on IOS devices was already implemented so i we want to have a more granular configuration the best choice is C because we are take in consdieration that this is an "old environment", if it was a new environment with switches that needs to be configured from scratch than option D would be the correct one
upvoted 2 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago