
CCIE Enterprise Infrastructure
Domain 4Objective 2
Network Security CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 3)
Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
3concepts
15%of the exam
Questions 11–15
- 11
An enterprise is deploying IPv6 in a multi-tenant environment. Each tenant has its own VLAN. The security team wants to prevent tenants from sending rogue router advertisements and also prevent them from spoofing IPv6 addresses. The switch supports RA guard, DHCPv6 guard, IPv6 source guard, and IPv6 ACLs. However, some tenants use static IPv6 addresses. Which configuration approach is most effective?
Select an answer first - 12
A network administrator is configuring a switch that connects to a server farm. The servers use static IP addresses. The security policy requires protection against ARP spoofing and also requires that the switch's CPU is protected from excessive broadcast traffic. The administrator has enabled DHCP snooping, but the servers are static. Which additional configuration is necessary to make DAI work effectively?
Select an answer first - 13
A network engineer is securing a router that runs BGP with multiple ISPs. The router also provides management access via SSH. The security team wants to ensure that only the ISP peers can establish BGP sessions, and that management access is restricted to a specific IPv4 host. The router is dual-stack. Which configuration is the most secure and efficient?
Select an answer first - 14
A service provider offers IPv6 Internet access to enterprise customers. The enterprise edge router receives IPv6 routing updates from the provider. The network team wants to ensure that only the provider's router can send routing updates and that no rogue IPv6 router advertisements are accepted on the customer-facing interface. Which two features should be implemented together?
Select an answer first - 15
A network administrator is configuring a new branch router. The security policy requires that only the network operations center (NOC) subnet can SSH to the router, and that the router's CPU is protected from excessive ICMP traffic. Additionally, the switch ports connecting to the branch's printers should only allow one MAC address each. Which set of configurations satisfies all requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.