
CCIE Enterprise Infrastructure
Domain 4Objective 1
Device Security on Cisco IOS XE CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 5)
Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
10concepts
15%of the exam
Questions 21–25
- 21
A network engineer is implementing CoPP on a Cisco IOS XE router to protect the route processor from excessive ICMP traffic. The engineer has created a class map that matches ICMP packets destined to the router's IP addresses. Which additional configuration is required to apply the policy to the control plane?
Select an answer first - 22
A network administrator wants to implement AAA on a router to ensure that users are authenticated, authorized for specific commands, and that all actions are logged. Which sequence of configuration steps is correct?
Select an answer first - 23
A network engineer is designing CoPP for a core router. The router must continue to receive routing protocol updates (OSPF, BGP) and allow SSH management, but must drop excessive ICMP and other unwanted traffic. The engineer wants to ensure that routing protocols are never dropped, even under attack. Which CoPP design is most appropriate?
Select an answer first - 24
A router is experiencing high CPU usage due to a flood of packets that are being process-switched and forwarded to the control plane. The engineer wants to use CPPr to police only these transit packets, but must ensure that packets destined to the router itself (like SSH) are not affected. Which CPPr configuration should be used?
Select an answer first - 25
An enterprise uses RADIUS for authentication and TACACS+ for authorization and accounting. The network team is configuring a new router and wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication, but if the TACACS+ server is unreachable, authorization should fail closed (deny access). Which configuration should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.