
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 4)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 16–20
- 16
A small business is deploying IBNS 2.0 and has a mix of devices: some support 802.1X, some are legacy devices that only support MAB, and some are guest devices that need web authentication. The business wants to ensure that all devices are authenticated and that guests are placed in a restricted VLAN. What is the best way to configure the switch to handle this?
Select an answer first - 17
A network administrator is troubleshooting an IBNS 2.0 deployment where users are authenticated but are not getting the correct VLAN assigned. The RADIUS server is returning the correct VLAN attribute. What is the most likely cause on the switch?
Select an answer first - 18
A large enterprise is deploying IBNS 2.0 across multiple sites. They have a requirement to enforce different access policies for employees, contractors, and guests. Employees should get full access, contractors should get limited access, and guests should only have internet access. They also want to enforce a session timeout of 8 hours for all users and reauthentication for employees every 24 hours. The network team is designing the C3PL policy. They have created a policy map with multiple class maps. However, they are unsure how to handle the reauthentication requirement for employees only. What is the best approach?
Select an answer first - 19
A company is implementing IBNS 2.0 and wants to use dACLs from Cisco ISE to enforce access control. They have configured ISE to return a dACL named 'DACL_EMPLOYEE' for employees and 'DACL_GUEST' for guests. On the switch, they have created a policy map that references these dACLs. However, when a guest authenticates, they are not getting the 'DACL_GUEST' applied; instead, they are getting the default ACL. What is the most likely cause?
Select an answer first - 20
A hospital is deploying IBNS 2.0 and wants to enforce posture assessment for all devices. They are using Cisco ISE as the RADIUS server. They have configured a policy that requires posture assessment for all users, and if a device is non-compliant, it should be placed in a quarantine VLAN. However, they are seeing that non-compliant devices are being placed in the quarantine VLAN, but they are not being re-assessed after remediation. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.