Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 18

4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 8)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts
25%of the exam

Questions 36–40

  1. 36expert · hard

    An enterprise is integrating IBNS 2.0 with LDAP for user authentication. The LDAP server contains user attributes such as department and clearance level. The network team wants to use these attributes to assign different VLANs. They are using Cisco ISE as the RADIUS server. What is the best way to achieve this?

    Select an answer first
  2. 37expert · hard · select all that apply

    A network architect is designing a C3PL policy for a campus network. The policy must support multiple authentication methods, dynamic VLAN assignment, and session timeout. Which of the following are valid components of a C3PL policy? (Select all that apply.)

    Select an answer first
  3. 38expert · hard · select all that apply

    A company is implementing IBNS 2.0 to enforce access control based on user identity. The RADIUS server returns a downloadable ACL (dACL) for certain users. The switch must apply this dACL. Which of the following are true regarding dACL enforcement? (Select all that apply.)

    Select an answer first
  4. 39expert · hard · select all that apply

    A network admin is troubleshooting an IBNS 2.0 deployment where 802.1X authentication is failing intermittently. The RADIUS server logs show that some Access-Requests are not receiving responses. The admin suspects a RADIUS communication issue. Which of the following could cause this? (Select all that apply.)

    Select an answer first
  5. 40expert · hard · select all that apply

    A security team is configuring user policy enforcement in IBNS 2.0. They want to enforce session timeout, reauthentication, and posture assessment. Which of the following are valid methods to enforce these policies? (Select all that apply.)

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.