
CCIE Security
Domain 2Objective 1
2.1 Cisco AnyConnect Client-Based, Remote-Access VPN Technologies on Cisco ASA, Cisco FTD, and Cisco Routers CCIE-SECURITY Practice Questions (Page 5)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
15concepts
20%of the exam
Questions 21–25
- 21
A company is deploying AnyConnect on an ASA for a group of contractors. The contractors should only access a specific internal web server (10.10.10.50) and must not have access to other internal subnets. The ASA has a pool of addresses (192.168.10.100-150) for VPN clients. Which configuration approach best meets the requirement?
Select an answer first - 22
A company wants to integrate AnyConnect with Cisco Umbrella to enforce DNS security for remote users. They have an ASA headend. What is the recommended way to achieve this?
Select an answer first - 23
A company is planning to deploy AnyConnect to 500 remote users. They need to ensure they have the appropriate licensing. Which license is required for AnyConnect Plus?
Select an answer first - 24
A large enterprise is deploying AnyConnect on a pair of ASAs in active/standby failover. They want to support both SSL and IPsec IKEv2 connections. They also need to ensure that if the active ASA fails, VPN sessions are preserved. Which configuration is required?
Select an answer first - 25
An administrator is troubleshooting slow performance on an AnyConnect VPN that uses SSL. They notice that DTLS is not being used. What is the most likely reason for DTLS not being negotiated?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.