
CCIE Security
Domain 2Objective 1
2.1 Cisco AnyConnect Client-Based, Remote-Access VPN Technologies on Cisco ASA, Cisco FTD, and Cisco Routers CCIE-SECURITY Practice Questions (Page 2)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
15concepts
20%of the exam
Questions 6–10
- 6
A network architect is designing a remote-access VPN solution using AnyConnect on an ASA. The requirement is to support both SSL and IPsec IKEv2 clients, but the ASA has limited resources. The architect wants to minimize the number of public IP addresses used. Which approach is most efficient?
Select an answer first - 7
An FTD device managed by FMC is configured for AnyConnect. The administrator needs to enforce that users from the 'Engineering' AD group get full tunnel access, while 'Contractor' users get split tunneling to only a specific subnet. The AD groups are returned as RADIUS attributes. Which configuration is required on FMC?
Select an answer first - 8
An IOS-XE router is configured for AnyConnect with IPsec IKEv2. The router uses a RADIUS server for authentication. The administrator wants to assign a specific access list to the VPN client session based on the RADIUS Filter-Id attribute. Which configuration is required?
Select an answer first - 9
A company is deploying AnyConnect to a diverse user base. They need to ensure that the client automatically connects to the correct VPN headend based on the user's location, and that split tunneling is configured differently for different user groups. Which two methods can be used to achieve this? (Select all that apply.)
Select an answer first - 10
An ASA is configured with AnyConnect and DAP. The DAP policy is set to require a specific posture attribute (AVG antivirus) for full access. Users with a different antivirus are denied. The administrator wants to allow users with a different antivirus but restrict them to a limited network. How should the DAP be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.