
CCIE Security
Domain 4Objective 6
4.6 BYOD On-Boarding and Network Access Flows CCIE-SECURITY Practice Questions (Page 4)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
25%of the exam
Questions 16–20
- 16
An enterprise wants to support BYOD for both corporate-owned and personal devices. Corporate-owned devices must have full access, while personal devices should only have internet access. They also want to use certificate-based authentication for corporate devices and username/password for personal devices. The network uses a single SSID. What is the best way to differentiate the access?
Select an answer first - 17
A company is deploying BYOD with 802.1X and uses a RADIUS server that integrates with Active Directory. They want to enforce a policy that only allows devices with a specific certificate issuer (the corporate CA) to access the corporate network. Personal devices without a certificate should be redirected to a guest network. How can this be achieved?
Select an answer first - 18
A hospital allows doctors to use personal tablets for accessing patient records. The security team wants to enforce that only devices with a compliant posture (e.g., no jailbreak, up-to-date OS) can access the records. They also want to allow non-compliant devices to access the internet for general use. The network uses 802.1X with RADIUS and dynamic VLANs. What is the best way to implement this?
Select an answer first - 19
A company uses a third-party cloud identity provider (IdP) for SSO. They want to allow BYOD devices to authenticate to the network using the same credentials. The network uses 802.1X with RADIUS. However, the IdP does not support RADIUS directly. What is the best way to integrate the IdP with the network access flow?
Select an answer first - 20
A university has a BYOD network using 802.1X with EAP-TLS. Students are issued certificates from the university CA. Recently, some students report that they cannot connect, and the RADIUS logs show 'certificate validation failed'. The certificates are not expired, and the CA is trusted. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.