Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 18

4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 3)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts
25%of the exam

Questions 11–15

  1. 11foundation · easy

    In an IBNS 2.0 deployment, which authentication method is most appropriate for a guest user connecting via a web browser without any pre-installed supplicant?

    Select an answer first
  2. 12foundation · easy

    In IBNS 2.0, which C3PL action can be used to dynamically assign a user to a specific VLAN based on the authentication result?

    Select an answer first
  3. 13foundation · easy

    What is the purpose of a downloadable ACL (dACL) in IBNS 2.0 access control enforcement?

    Select an answer first
  4. 14foundation · easy

    Which C3PL parameter is used to enforce a maximum duration for an authenticated session, after which the user must reauthenticate?

    Select an answer first
  5. 15application · medium

    A university is deploying IBNS 2.0 to control network access in dormitories. They need to support a mix of devices: some with 802.1X supplicants, some legacy devices without supplicants, and guests who will authenticate via a web portal. The network team wants a single policy framework to define authentication methods and fallback behavior. Which approach best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.