ISE TACACS+ Profile for Full ASA Admin Access Without Enable?

Configure TACACS+ device administration, command authorization, and accounting
Answer Correct answer: D, E — In the ISE TACACS+ profile set Default and Maximum Privilege to 15, and permit any command not listed, so the AD admin gets full ASA access without enable.

An administrator must configure Cisco ISE to authenticate the administrative superuser to manage a Cisco Adaptive Security Appliance firewall. The solution must meet the requirements: • The user must be authenticated against Microsoft AD. • The user must have full management administrative access to the Cisco Adaptive Security Appliance firewall. • The user must not use the enable command. The configurations were performed: • joined Cisco ISE to AD and retrieved AD groups • added the Cisco Adaptive Security Appliance firewall • enabled Device Admin Service in Cisco ISE • configured TACACS command sets • configured a TACACS profile • configured an authorization policy • configured the Cisco Adaptive Security Appliance firewall for authentication and authorization Which two actions must be performed in Cisco ISE? (Choose two.)

  1. Configure an authentication profile on Cisco ISE.
  2. Set Default Privilege to 1 and Maximum Privilege to 15 in the TACACS profile.
  3. Add all authorized admin commands to the TACACS profile.
  4. Set Default Privilege to 15 and Maximum Privilege to 15 in the TACACS profile. Correct Answer
  5. Select "Permit any command that is not listed below" in the TACACS profile. Correct Answer

Community Votes

DE
100%

100% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests how ISE TACACS+ privilege-level defaults and command-set behavior deliver Device Admin authorization; the trap is picking Default Privilege 1, which silently reintroduces the enable command the requirements forbid.

To give an AD-authenticated superuser full management access to a Cisco ASA without ever typing enable, the ISE TACACS+ profile must return Default Privilege 15 and Maximum Privilege 15 (D), and the referenced command set must permit unlisted commands (E). These two actions complete the Device Admin configuration already staged with command sets, profile, authorization policy and the ASA.

Choosing Default Privilege 1 / Maximum Privilege 15 (option B) because escalation to 15 feels like standard practice — but a default of 1 lands the admin in user exec and requires enable, directly violating the stated requirement.

Community Discussion (3 comments)

Cachaman 👍 1 Selected: DE
D and E
luismg 👍 1 Selected: DE
D is clear is asking for full privilege out of the box E is used not to exclude any command
one_1996 👍 1 Selected: DE
in the tacacs+ profile to have full access to all commands you must put "Permit any command that is not listed below" and you must set 15 as Default and maximum Privilage

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement "the user must not use the enable command" is a direct constraint on the privilege level ISE returns in the TACACS+ authorization response: the Default Privilege in the TACACS+ profile is the level the administrator lands in at login, and Maximum Privilege is the ceiling for any further escalation. Setting both to 15 (option D) puts the AD superuser straight into privilege-15 EXEC with no enable step, satisfying both the "full management administrative access" and "no enable" requirements at once. Option E, "Permit any command that is not listed below," is the command-set behaviour that the TACACS+ profile references, and it is what actually grants unrestricted command authority: with the default deny posture, any privileged command not explicitly enumerated in the command set would be rejected. Together D and E complement the artifacts already built (command sets, TACACS profile, authorization policy, ASA TACACS configuration) and produce full ASA management access for the AD user. This is also the unanimous reading of the community comments on the page.

Why the Other Options Are Wrong

Option A is a distractor: authentication profiles in ISE describe how a supplicant authenticates (for example EAP methods for 802.1X or MAB), whereas TACACS+ Device Admin authentication simply points at the AD identity source inside the authentication policy — and ISE is already joined to AD with the authorization policy configured. Option B sets Default Privilege 1 with Maximum 15, which is precisely the scenario that forces the administrator to type enable to climb from user exec to privileged exec, contradicting an explicit requirement. Option C asks you to enumerate every authorized admin command in the TACACS profile; that is impractical, unmaintainable and unnecessary when the command set already offers a blanket "permit any command that is not listed below" option that yields the same full-access result. Nothing in the question suggests a restricted command list, so a per-command allow list would be over-engineering and would still depend on option E's behaviour for anything omitted.

Community Comment Notes

Every learner who voted landed on D and E. As luismg put it, D gives the admin "full privilege out of the box" while E exists "not to exclude any command." one_1996 reinforced the pairing, noting that for full access you must select "Permit any command that is not listed below" and set 15 as both Default and Maximum privilege in the TACACS+ profile. Cachaman simply confirmed "D and E." No commenter defended Default Privilege 1 or an enumerated command list, so the source key and the community agree with the analysis above.

Note on the wording: ISE exposes the "Permit any command that is not listed below" radio button inside the command set that the TACACS+ profile references; the exam treats it as part of completing the TACACS+ profile configuration.

Exam Strategy

Read the requirement list first and treat "must not use the enable command" as a hard filter: it immediately eliminates any answer with Default Privilege 1, including the tempting 1/15 combination. Then ask what grants unrestricted commands — a blanket permit-unlisted setting, not a manual list of every command.

Frequently Asked Questions

Why must Default Privilege be 15 instead of 1 in the ISE TACACS+ profile?

ISE returns the Default Privilege in the TACACS+ authorization reply; a value of 1 puts the admin in user exec, forcing the enable command that the requirement explicitly forbids.

Why not list every authorized admin command in the TACACS profile instead of option E?

Enumerating all commands is impractical and error-prone; selecting "Permit any command that is not listed below" grants full access while still allowing explicit denies.

Related Analysis

← Back to 300-715 Study Guide