
CCIE Security
Domain 2Objective 2
2.2 Cisco IOS CA for VPN Authentication CCIE-SECURITY Practice Questions (Page 4)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
20%of the exam
Questions 16–20
- 16
An engineer is configuring a remote-access VPN on a Cisco ASA (which uses similar certificate concepts) with certificates from a Cisco IOS CA. The VPN works for most users, but one user's certificate is rejected. The user's certificate was enrolled correctly and is not expired. The CA's CRL is accessible. What is the most likely reason for this specific user's failure?
Select an answer first - 17
A VPN gateway is configured to use CRL checking, but the CRL is hosted on a server that is occasionally unreachable. The administrator wants to ensure that VPN connections are not disrupted when the CRL server is down. What is the best configuration?
Select an answer first - 18
A Cisco IOS CA is configured, and a VPN peer is attempting to enroll via SCEP. The peer sends a certificate request, but the CA does not issue a certificate. The CA's log shows 'enrollment request rejected'. What is the most likely cause?
Select an answer first - 19
A security architect is designing a VPN solution using a Cisco IOS CA. The company requires that all VPN peers be authenticated using certificates, and that the CA be highly available. Which design is most appropriate?
Select an answer first - 20
A VPN peer is unable to establish an IPsec tunnel using certificates. The peer's certificate is valid and trusted, but the gateway's log shows 'no suitable certificate found'. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.