Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 12

4.12 Certification-Based Authentication Using Cisco ISE CCIE-SECURITY Practice Questions (Page 6)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts
25%of the exam

Questions 26–30

  1. 26application · medium

    An organization uses Cisco ISE for wired authentication. They want to use PEAP-MSCHAPv2 for user authentication, but they also want to ensure that the server certificate is trusted by clients. What must be configured on the clients to achieve this?

    Select an answer first
  2. 27application · medium

    A financial firm is planning to replace their current password-based Wi-Fi authentication with a more secure method. They want to eliminate the risk of password phishing and ensure that only company-managed devices can access the network. Which authentication method should they implement?

    Select an answer first
  3. 28application · medium

    A university wants to deploy certificate-based authentication for both students and faculty. Students will use personal devices, while faculty will use university-issued laptops. The university wants to automate certificate enrollment for faculty devices but not for student devices. What is the best approach?

    Select an answer first
  4. 29application · medium

    During a pilot of EAP-TLS, some users can authenticate successfully while others cannot. The failing users have certificates issued by a different subordinate CA under the same root CA. ISE has the root CA and one subordinate CA in its trust store. What is the most likely issue?

    Select an answer first
  5. 30application · medium

    A company uses Cisco ISE for 802.1X authentication. They want to allow only devices that have a certificate with the Organizational Unit (OU) 'Engineering' to access the network. Which ISE policy component should be used to enforce this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.