Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 2Objective 2

2.2 Cisco IOS CA for VPN Authentication CCIE-SECURITY Practice Questions (Page 6)

Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
20%of the exam

Questions 26–30

  1. 26application · medium

    An engineer is configuring a site-to-site IPsec VPN between two routers, both using certificates from the same Cisco IOS CA. The VPN fails to establish, and the logs show 'certificate validation failed'. The certificates were enrolled successfully. What should the engineer check first?

    Select an answer first
  2. 27application · medium

    A VPN peer successfully enrolls with a Cisco IOS CA via SCEP, but when it tries to establish an IPsec tunnel, the gateway rejects the certificate. The gateway's log shows 'certificate not yet valid'. What is the most likely cause?

    Select an answer first
  3. 28application · medium

    A company wants to use a Cisco IOS router as a CA for its VPN. The router is already configured with a hostname and domain name. The engineer enables the CA server and generates a CA certificate. However, when a peer tries to enroll, it receives an error that the CA certificate is not trusted. What is the missing configuration?

    Select an answer first
  4. 29application · medium

    An IPsec VPN is configured to use certificates for authentication. The VPN gateway is supposed to accept connections only from peers whose certificates contain a specific organizational unit (OU) in the subject. How should the engineer configure the gateway to enforce this?

    Select an answer first
  5. 30application · medium

    A Cisco IOS CA is used for VPN authentication. The administrator wants to ensure that revoked certificates are quickly rejected by VPN gateways. The CA supports both CRL and OCSP. Which configuration should be used to minimize the time between revocation and enforcement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.