
CCIE Enterprise Infrastructure
Domain 4Objective 2
Network Security CCIE-ENTERPRISE-INFRASTRUCTURE Practice Questions (Page 7)
Part of the Infrastructure Security and Services domain, which accounts for 15% of the CCIE-ENTERPRISE-INFRASTRUCTURE exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
3concepts
15%of the exam
Questions 31–35
- 31
A network administrator is troubleshooting a user's inability to reach the internet. The access switch has DHCP snooping enabled. The user's PC is connected to port Gi1/0/5, which is configured as an untrusted port. The PC successfully obtained an IP address from the DHCP server, but traffic from the PC is being dropped. What is the most likely cause?
Select an answer first - 32
A network administrator is designing a secure access layer for a new building. The requirements are: (1) prevent DHCP starvation, (2) prevent ARP spoofing, (3) prevent IP spoofing, and (4) limit broadcast storms. Which of the following features should be enabled on user-facing ports? (Select all that apply.)
Select an answer first - 33
A network engineer is configuring a new access layer switch for a secure campus deployment. The requirements are: (1) prevent DHCP starvation attacks from user ports, (2) prevent ARP spoofing, and (3) limit the number of MAC addresses per port. Which combination of features should be enabled on user-facing ports?
Select an answer first - 34
A network administrator needs to secure management access to a Cisco router. The requirements are: (1) use AAA for authentication, (2) restrict management access to a specific subnet, and (3) protect the control plane from excessive traffic. Which configuration approach best meets these requirements?
Select an answer first - 35
A network engineer is configuring a router that connects to an untrusted external network. The requirement is to prevent IP spoofing attacks where an attacker sends packets with a source address from the internal network. Which feature should be enabled on the external interface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-ENTERPRISE-INFRASTRUCTURE” is a trademark of its owner, used for identification only.