An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+. However, the administrator must restrict certain commands based on one of three user roles that require different commands.
How is this accomplished without creating too many objects using Cisco ISE?
A. Create one shell profile and one command set.
B. Create multiple shell profile and one command set.
C. Create multiple shell profile and multiple command sets.
D. Create one shell profile and multiple command sets.
I believe the answer should be D
I think more than one shell profile is needed to make sure it is assigned to different users or roles.
Having only one, it would not allow other roles to have different command sets.