
CCIE Security
Domain 4Objective 12
4.12 Certification-Based Authentication Using Cisco ISE CCIE-SECURITY Practice Questions (Page 7)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
25%of the exam
Questions 31–35
- 31
An organization wants to use EAP-FAST for wireless authentication. They want to use certificates for server-side authentication but do not want to deploy client certificates. Which EAP-FAST configuration should be used?
Select an answer first - 32
A company is deploying Cisco ISE for wireless network access. They want to use certificate-based authentication with EAP-TLS for all corporate laptops. The laptops have certificates issued by an internal CA. The ISE admin needs to configure the authentication policy to accept only these certificates and reject all others. What should the admin configure in the authentication policy?
Select an answer first - 33
A company uses EAP-FAST with PAC files for wireless authentication. They want to enhance security by using certificates for the server-side authentication. What is the required configuration in Cisco ISE?
Select an answer first - 34
An ISE admin is troubleshooting a certificate-based authentication issue. The logs show 'Authentication failed: Certificate validation failed - Certificate is not yet valid'. The client certificate was just issued. What is the most likely cause?
Select an answer first - 35
An ISE admin is configuring EAP-TLS and wants to ensure that only certificates with a specific Extended Key Usage (EKU) of 'Client Authentication' are accepted. The admin has imported the CA certificate and configured the authentication policy to use 'Certificate Authentication'. What additional configuration is needed to enforce the EKU requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.