
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 7)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 31–35
- 31
A network admin is troubleshooting an IBNS 2.0 issue where 802.1X authentication works for some users but not others. The failing users are in the same VLAN and use the same switch. The RADIUS server logs show that the Access-Request is received but no Access-Accept is sent. What is the most likely cause?
Select an answer first - 32
A large enterprise is redesigning its network access control. They have a mix of legacy switches that do not support IBNS 2.0 and newer switches that do. The security team wants a consistent policy enforcement across all switches. They are considering deploying Cisco ISE as the RADIUS server. What is the best approach to achieve consistent policy enforcement?
Select an answer first - 33
An administrator is troubleshooting an IBNS 2.0 deployment where users authenticate successfully but are not getting the correct VLAN assigned. The RADIUS server is sending the correct Tunnel-Private-Group-ID, but the switch is placing users in the default VLAN. The switch configuration includes the command 'aaa authorization network default group radius'. What is the most likely cause?
Select an answer first - 34
A security team is implementing posture assessment for remote workers connecting via VPN. They want to enforce that only compliant devices can access the corporate network. The VPN gateway supports IBNS 2.0-like policies. The team is debating whether to use session-timeout or CoA to enforce posture rechecks. What is the best approach?
Select an answer first - 35
A network admin is configuring IBNS 2.0 on a switch that connects to a mix of 802.1X-capable and non-802.1X devices. The requirement is that 802.1X-capable devices must authenticate via 802.1X, while non-capable devices should fall back to MAB. The admin has configured the policy map with 'authentication priority dot1x mab'. However, some non-802.1X devices are failing MAB. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.