Which combination of TACACS+ device administration design practices would provide secure, auditable, and appropriately scoped administrative access across a large network infrastructure?
Correct Answer: Role-based command sets and shell profiles scoped to administrator identity groups, correctly matched shared secrets on every device, and centralized policy management through ISE's TACACS+ device administration features
Explanation: Role-based command sets, correctly matched shared secrets, and centralized ISE policy management together provide secure, auditable, scoped access, unlike a single shared account/password for all devices, no command sets with universal full access, unresolved mismatched shared secrets, fully decentralized manual configuration, or disabling accounting entirely.
Correct Answer: Role-based command sets and shell profiles scoped to administrator identity groups, correctly matched shared secrets on every device, and centralized policy management through ISE's TACACS+ device administration features
Explanation: Role-based command sets, correctly matched shared secrets, and centralized ISE policy management together provide secure, auditable, scoped access, unlike a single shared account/password for all devices, no command sets with universal full access, unresolved mismatched shared secrets, fully decentralized manual configuration, or disabling accounting entirely.