
CCIE Enterprise Infrastructure
Domain 4Objective 2
Network Security CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 1)
Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
3concepts
15%of the exam
Questions 1–5
- 1
Which Layer 2 security feature on a Cisco switch validates the source IP address of IP packets received on a port against the DHCP snooping binding table?
Select an answer first - 2
Which switch security feature is primarily used to mitigate DHCP starvation attacks by limiting the rate of DHCP requests on an untrusted port?
Select an answer first - 3
Which router security feature is designed to protect the route processor from excessive or malicious traffic destined to the router itself?
Select an answer first - 4
Which router security feature verifies that the source IP address of a packet is reachable via the interface on which the packet was received, to mitigate IP spoofing?
Select an answer first - 5
Which IPv6-specific security feature is used to prevent rogue Router Advertisement (RA) messages from being sent on a segment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.