
CCIE Security
Domain 2Objective 1
2.1 Cisco AnyConnect Client-Based, Remote-Access VPN Technologies on Cisco ASA, Cisco FTD, and Cisco Routers CCIE-SECURITY Practice Questions (Page 7)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
15concepts
20%of the exam
Questions 31–35
- 31
An organization wants to enforce that only corporate-managed devices can access the VPN. They use AnyConnect with posture assessment. Which feature should be used to block non-compliant devices?
Select an answer first - 32
A network engineer is configuring AnyConnect on an IOS-XE router for a small branch office. They need to provide remote access for 20 users. The router will use a virtual-template interface for the VPN pool. Which configuration is required to allow AnyConnect clients to connect via SSL?
Select an answer first - 33
An organization wants to deploy AnyConnect to all employees with a pre-configured profile that automatically connects to the VPN and uses split tunneling to exclude local LAN traffic. They have an ASA headend. Which method should be used to deploy the profile?
Select an answer first - 34
A company is setting up AnyConnect on an ASA. They want to use RADIUS authentication against their existing Cisco ISE, and also want to assign different group policies based on the RADIUS class attribute. Which configuration is necessary on the ASA?
Select an answer first - 35
An organization wants to enforce different VPN access policies based on the user's device posture. For example, if the device has antivirus running, the user should get full access; otherwise, they should be restricted to a quarantine network. Which feature should be used on the ASA?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.