Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 2Objective 2

2.2 Cisco IOS CA for VPN Authentication CCIE-SECURITY Practice Questions (Page 9)

Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
20%of the exam

Questions 41–45

  1. 41expert · hard

    A security administrator is managing a Cisco IOS CA. A VPN gateway's certificate has been revoked, but the gateway continues to establish VPN tunnels. The administrator has verified that the gateway is configured to check the CRL. What is a possible reason the revoked certificate is still accepted?

    Select an answer first
  2. 42expert · hard

    A company is deploying a Cisco IOS CA and wants to automate certificate enrollment for a large number of VPN routers. They plan to use SCEP with a shared secret. However, the security team is concerned about the shared secret being compromised. What is the best way to mitigate this risk?

    Select an answer first
  3. 43application · medium

    A company is deploying a new remote-access VPN for teleworkers. The VPN gateway uses a Cisco IOS CA to issue certificates to client devices. The teleworkers' devices are not always online, and the IT team wants to minimize manual steps. Which enrollment method should be configured on the clients?

    Select an answer first
  4. 44expert · hard

    A network architect is designing a PKI for a large enterprise with multiple regional offices. They plan to use a single Cisco IOS CA at headquarters. However, the WAN links to some remote offices are unreliable, and certificate enrollment may fail. What is the best approach to ensure that remote routers can still obtain certificates?

    Select an answer first
  5. 45application · medium

    A VPN administrator is troubleshooting why a remote router cannot complete certificate enrollment with the Cisco IOS CA. The router generates a key pair and sends a certificate request, but the CA does not issue a certificate. The CA logs show 'certificate request rejected'. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.