
CCIE Security
Domain 2Objective 2
2.2 Cisco IOS CA for VPN Authentication CCIE-SECURITY Practice Questions (Page 8)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
20%of the exam
Questions 36–40
- 36
A company is deploying a Cisco IOS CA on a router that also serves as a VPN gateway. The router has limited CPU and memory. The CA will issue certificates to about 200 remote VPN clients. The security team requires that the CA's private key be stored securely and that the CA be able to issue certificates even if the router is rebooted. Which configuration approach best meets these requirements?
Select an answer first - 37
A VPN administrator is enrolling a new router with a Cisco IOS CA using SCEP. The router is behind a NAT and uses a private IP address. The CA is configured with a certificate policy that requires the subject name to include the router's hostname. The enrollment fails with 'subject name mismatch'. What is the most likely cause?
Select an answer first - 38
A company has a Cisco IOS CA and multiple VPN gateways. They want to use certificate-based authentication for site-to-site VPNs. The security team requires that if a VPN gateway's certificate is compromised, it can be revoked and the revocation information propagated quickly to all other gateways. The company has limited bandwidth and wants to minimize the overhead of revocation checking. Which approach is most appropriate?
Select an answer first - 39
A VPN tunnel between two routers using certificates from a Cisco IOS CA fails to establish. The debug output shows 'certificate validation failed' and 'unable to get local issuer certificate'. The routers are configured with the same trustpoint and have enrolled successfully. What is the most likely cause?
Select an answer first - 40
A network engineer is setting up a Cisco IOS CA on a router that also runs BGP and OSPF. The router has limited CPU. The CA will issue certificates to 50 VPN peers. The engineer wants to minimize the impact of the CA on the router's routing performance. Which configuration is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.