Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 13

4.13 Authentication Methods CCIE-SECURITY Practice Questions (Page 6)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
8concepts
25%of the exam

Questions 26–30

  1. 26application · medium

    An organization wants to use TEAP with EAP chaining to perform both machine and user authentication in a single EAP session. They are using Cisco ISE. What is the primary benefit of this approach compared to separate machine and user authentications?

    Select an answer first
  2. 27application · medium

    A network administrator is configuring TEAP with EAP chaining for a deployment that requires both machine and user authentication. They want to ensure that the session keys derived from each inner method are used correctly. What should they be aware of?

    Select an answer first
  3. 28application · medium

    A security team is evaluating TEAP inner methods for a deployment that requires strong security and support for both password and certificate authentication. They are concerned about the security of EAP-MSCHAPv2. What is a valid security consideration?

    Select an answer first
  4. 29application · medium

    A university is deploying a new Wi-Fi network for students and faculty. The security team requires that both the user's Active Directory credentials and the device's machine certificate be validated before granting network access. They also need to support a wide range of supplicants, including legacy Windows 7 laptops that do not support the latest protocols. The team has decided to use Cisco ISE as the RADIUS server. Which EAP method should the team configure on the wireless LAN controller to meet these requirements?

    Select an answer first
  5. 30expert · hard

    A security architect is designing a TEAP deployment for a high-security government agency. The agency requires that all authentication traffic be protected against man-in-the-middle attacks and that the inner methods provide mutual authentication. The architect is considering using EAP-GTC as an inner method. What is the primary security concern with using EAP-GTC in this context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.