
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 5)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 21–25
- 21
A company is integrating IBNS 2.0 with Cisco ISE and using LDAP as the identity source. They want to use the LDAP attribute 'department' to assign different VLANs. They have configured ISE to return the department attribute in the RADIUS response. On the switch, they have created a class map that matches on the RADIUS attribute 'department' with value 'engineering'. However, when an engineering user authenticates, they are not getting the correct VLAN. What is the most likely cause?
Select an answer first - 22
A network administrator is troubleshooting an IBNS 2.0 deployment where 802.1X authentication is failing for some users. The RADIUS server logs show that the authentication request is being sent, but the response is not being received by the switch. The switch's RADIUS server configuration is correct. What is the most likely cause?
Select an answer first - 23
A company is deploying IBNS 2.0 and wants to support a variety of devices. They have a mix of 802.1X-capable devices, legacy devices that only support MAB, and guest devices that need web authentication. They want to ensure that all devices are authenticated and that guests are placed in a restricted VLAN. Which of the following configurations are necessary to achieve this? (Select all that apply.)
Select an answer first - 24
A company is implementing IBNS 2.0 to enforce different access policies for employees and contractors. They want to use Cisco ISE as the RADIUS server and assign different VLANs based on user role. The network team is designing the C3PL policy on the switch. What is the correct way to structure the policy to achieve role-based VLAN assignment?
Select an answer first - 25
A hospital is deploying IBNS 2.0 for its wired network. They have a mix of devices: IP phones (which do not support 802.1X), Windows laptops (which do), and guest devices that need web authentication. The network team wants to ensure that IP phones are authenticated using their MAC address, while laptops use 802.1X. What configuration approach should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.