Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 12

4.12 Certification-Based Authentication Using Cisco ISE CCIE-SECURITY Practice Questions (Page 4)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts
25%of the exam

Questions 16–20

  1. 16foundation · easy

    In EAP-TLS authentication, what is required on the client side?

    Select an answer first
  2. 17application · medium

    A hospital network uses Cisco ISE for wireless access. They want to deploy certificate-based authentication for all staff laptops using EAP-TLS. The security team requires that only devices with a valid certificate from the internal CA and a certificate that has not been revoked are allowed. Which configuration in Cisco ISE is essential to meet this requirement?

    Select an answer first
  3. 18application · medium

    A company wants to authenticate both the machine and the user for network access. They have deployed machine certificates to all company laptops and user certificates to all employees. The requirement is that both machine and user must be authenticated before granting access. Which EAP method should be used?

    Select an answer first
  4. 19expert · hard

    A network administrator is troubleshooting EAP-TLS authentication failures. The ISE logs show 'Certificate validation failed' for a specific user, but other users with certificates from the same CA can authenticate. The user's certificate is not expired and the CRL is reachable. What should the administrator check next?

    Select an answer first
  5. 20expert · hard

    An organization is deploying EAP-TLS and has a two-tier PKI: a root CA and multiple issuing CAs. ISE has the root CA certificate in its trust store, but not the issuing CA certificates. During testing, all client certificates fail validation. What is the most efficient solution?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.