
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 3)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 11–15
- 11
In an IBNS 2.0 deployment, which authentication method is most appropriate for a guest user connecting via a web browser without any pre-installed supplicant?
Select an answer first - 12
In IBNS 2.0, which C3PL action can be used to dynamically assign a user to a specific VLAN based on the authentication result?
Select an answer first - 13
What is the purpose of a downloadable ACL (dACL) in IBNS 2.0 access control enforcement?
Select an answer first - 14
Which C3PL parameter is used to enforce a maximum duration for an authenticated session, after which the user must reauthenticate?
Select an answer first - 15
A university is deploying IBNS 2.0 to control network access in dormitories. They need to support a mix of devices: some with 802.1X supplicants, some legacy devices without supplicants, and guests who will authenticate via a web portal. The network team wants a single policy framework to define authentication methods and fallback behavior. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.