Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Enterprise Infrastructure

Domain 4Objective 2

Network Security CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 2)

Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
3concepts
15%of the exam

Questions 6–10

  1. 6foundation · easy

    Which IPv6 security measure is used to authenticate OSPFv3 routing updates?

    Select an answer first
  2. 7application · medium

    A network engineer is hardening a campus access layer. The switch connects to end-user PCs and IP phones. The requirement is to prevent MAC flooding attacks while allowing the IP phone to register with the call manager. The engineer also needs to ensure that only the IT department's management station can SSH to the switch. Which configuration approach meets both requirements?

    Select an answer first
  3. 8expert · hard

    A dual-stack router is being deployed at a branch office. The router connects to an ISP via BGP and also provides internal routing via OSPFv3. The security policy requires that BGP sessions are authenticated, OSPFv3 updates are encrypted, and management access is restricted to a specific IPv6 host. The router also needs to prevent IP spoofing on the ISP-facing interface. Which set of configurations best meets all requirements?

    Select an answer first
  4. 9expert · hard

    A large campus network is experiencing ARP spoofing attacks in the access layer. The network uses both IPv4 and IPv6. The security team wants to implement a comprehensive solution that prevents ARP spoofing, IPv6 neighbor discovery spoofing, and also protects the switch CPU from control plane floods. The switches are capable of DHCP snooping, DAI, RA guard, and CoPP. Which combination of features should be enabled?

    Select an answer first
  5. 10expert · hard

    A network engineer is troubleshooting a router that is dropping legitimate OSPFv3 packets. The router has an IPv6 ACL applied to the VTY lines, CoPP policy, and uRPF on the WAN interface. The OSPFv3 neighbor is on the WAN interface. Which configuration is most likely causing the drops?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.