ISE TACACS+ Profile for Full ASA Admin Access Without Enable?
An administrator must configure Cisco ISE to authenticate the administrative superuser to manage a Cisco Adaptive Security Appliance firewall. The solution must meet the requirements: • The user must be authenticated against Microsoft AD. • The user must have full management administrative access to the Cisco Adaptive Security Appliance firewall. • The user must not use the enable command. The configurations were performed: • joined Cisco ISE to AD and retrieved AD groups • added the Cisco Adaptive Security Appliance firewall • enabled Device Admin Service in Cisco ISE • configured TACACS command sets • configured a TACACS profile • configured an authorization policy • configured the Cisco Adaptive Security Appliance firewall for authentication and authorization Which two actions must be performed in Cisco ISE? (Choose two.)
Community Votes
100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This item tests how ISE TACACS+ privilege-level defaults and command-set behavior deliver Device Admin authorization; the trap is picking Default Privilege 1, which silently reintroduces the enable command the requirements forbid.
To give an AD-authenticated superuser full management access to a Cisco ASA without ever typing enable, the ISE TACACS+ profile must return Default Privilege 15 and Maximum Privilege 15 (D), and the referenced command set must permit unlisted commands (E). These two actions complete the Device Admin configuration already staged with command sets, profile, authorization policy and the ASA.
Choosing Default Privilege 1 / Maximum Privilege 15 (option B) because escalation to 15 feels like standard practice — but a default of 1 lands the admin in user exec and requires enable, directly violating the stated requirement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement "the user must not use the enable command" is a direct constraint on the privilege level ISE returns in the TACACS+ authorization response: the Default Privilege in the TACACS+ profile is the level the administrator lands in at login, and Maximum Privilege is the ceiling for any further escalation. Setting both to 15 (option D) puts the AD superuser straight into privilege-15 EXEC with no enable step, satisfying both the "full management administrative access" and "no enable" requirements at once. Option E, "Permit any command that is not listed below," is the command-set behaviour that the TACACS+ profile references, and it is what actually grants unrestricted command authority: with the default deny posture, any privileged command not explicitly enumerated in the command set would be rejected. Together D and E complement the artifacts already built (command sets, TACACS profile, authorization policy, ASA TACACS configuration) and produce full ASA management access for the AD user. This is also the unanimous reading of the community comments on the page.Why the Other Options Are Wrong
Option A is a distractor: authentication profiles in ISE describe how a supplicant authenticates (for example EAP methods for 802.1X or MAB), whereas TACACS+ Device Admin authentication simply points at the AD identity source inside the authentication policy — and ISE is already joined to AD with the authorization policy configured. Option B sets Default Privilege 1 with Maximum 15, which is precisely the scenario that forces the administrator to type enable to climb from user exec to privileged exec, contradicting an explicit requirement. Option C asks you to enumerate every authorized admin command in the TACACS profile; that is impractical, unmaintainable and unnecessary when the command set already offers a blanket "permit any command that is not listed below" option that yields the same full-access result. Nothing in the question suggests a restricted command list, so a per-command allow list would be over-engineering and would still depend on option E's behaviour for anything omitted.Community Comment Notes
Every learner who voted landed on D and E. As luismg put it, D gives the admin "full privilege out of the box" while E exists "not to exclude any command." one_1996 reinforced the pairing, noting that for full access you must select "Permit any command that is not listed below" and set 15 as both Default and Maximum privilege in the TACACS+ profile. Cachaman simply confirmed "D and E." No commenter defended Default Privilege 1 or an enumerated command list, so the source key and the community agree with the analysis above.Note on the wording: ISE exposes the "Permit any command that is not listed below" radio button inside the command set that the TACACS+ profile references; the exam treats it as part of completing the TACACS+ profile configuration.
Exam Strategy
Read the requirement list first and treat "must not use the enable command" as a hard filter: it immediately eliminates any answer with Default Privilege 1, including the tempting 1/15 combination. Then ask what grants unrestricted commands — a blanket permit-unlisted setting, not a manual list of every command.
Frequently Asked Questions
Why must Default Privilege be 15 instead of 1 in the ISE TACACS+ profile?
ISE returns the Default Privilege in the TACACS+ authorization reply; a value of 1 puts the admin in user exec, forcing the enable command that the requirement explicitly forbids.
Why not list every authorized admin command in the TACACS profile instead of option E?
Enumerating all commands is impractical and error-prone; selecting "Permit any command that is not listed below" grants full access while still allowing explicit denies.