
CCIE Security
Domain 2Objective 1
2.1 Cisco AnyConnect Client-Based, Remote-Access VPN Technologies on Cisco ASA, Cisco FTD, and Cisco Routers CCIE-SECURITY Practice Questions (Page 6)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
15concepts
20%of the exam
Questions 26–30
- 26
An FTD device is managed by FMC. The security team wants to implement a DAP that grants full access only if the user is in the 'FullAccess' AD group and the device posture is compliant. Otherwise, the user should be placed in a quarantine network. Which of the following are required to implement this? (Select all that apply.)
Select an answer first - 27
An IOS-XE router is configured for AnyConnect SSL VPN. Users report that they can connect but cannot access internal resources. The router has a virtual-template interface with an IP pool of 192.168.1.0/24. The internal network is 10.0.0.0/8. The router has a static route to 10.0.0.0/8 via the inside interface. What is the most likely issue?
Select an answer first - 28
A company has multiple ASAs in different locations. They want to load balance AnyConnect connections across these ASAs. They also want to ensure that if one ASA fails, users are automatically redirected to another. Which solution should they implement?
Select an answer first - 29
An administrator is troubleshooting an AnyConnect connection issue. The user can connect but immediately disconnects. The ASA logs show 'SSL certificate verification failed' errors. What is the most likely cause?
Select an answer first - 30
An organization is migrating from ASA to FTD with FMC. They need to configure AnyConnect remote-access VPN for employees. The security policy requires that only users who are members of the 'VPN-Allowed' AD group can connect, and they must use two-factor authentication. Which configuration steps are required on FMC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.