
CCIE Enterprise Infrastructure
Domain 4Objective 2
Network Security CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 4)
Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
3concepts
15%of the exam
Questions 16–20
- 16
An enterprise is deploying IPv6 in its access layer. The security team wants to prevent rogue DHCPv6 servers from assigning addresses and also prevent unauthorized devices from spoofing IPv6 addresses on the network. The switches are capable of Layer 2 security features. Which combination of features should be enabled on the access switches?
Select an answer first - 17
A network engineer is securing a dual-stack router that connects to an untrusted external network. The router runs BGP with an ISP and also provides management access via SSH. The security policy requires that only the ISP's BGP peer can establish BGP sessions, and that management access is restricted to a specific IPv6 management host. Which configuration approach meets these requirements?
Select an answer first - 18
A switch in a data center connects to multiple servers. The security team wants to prevent ARP spoofing attacks and also ensure that the switch's CPU is not overwhelmed by broadcast traffic. The servers use static IP addresses. Which two features should be enabled on the switch?
Select an answer first - 19
An enterprise is migrating to IPv6. The access switches are connected to end-user devices. The security team wants to block rogue IPv6 router advertisements and also prevent unauthorized devices from sending IPv6 traffic with spoofed source addresses. Which two features should be enabled on the access switches?
Select an answer first - 20
A branch office switch connects to a distribution switch via a trunk port. The network team wants to prevent a rogue switch from being plugged into an access port and becoming the root bridge. They also want to limit the number of MAC addresses learned on that access port to two. Which configuration on the access port meets both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.