Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 6

1.6 Cisco NGFW Features CCIE-SECURITY Practice Questions (Page 6)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
11concepts
20%of the exam

Questions 26–30

  1. 26expert · hard

    A company has a Cisco NGFW that is integrated with Active Directory. They want to enforce a policy that blocks file-sharing applications for all users, except for the 'Engineering' group, which needs to use a specific file-sharing tool for collaboration. However, the Engineering group also uses other file-sharing apps that should be blocked. The NGFW's AVC identifies the specific tool by its signature. What is the best way to implement this?

    Select an answer first
  2. 27expert · hard

    A global company wants to block all traffic from high-risk countries, but they have branch offices in some of those countries that need to access the corporate network via VPN. The NGFW is also used for AVC and user identity. The VPN traffic from those branches comes from the same IP ranges as the country's general traffic. What is the best way to allow the branch office traffic while blocking other traffic from those countries?

    Select an answer first
  3. 28expert · hard

    An organization is implementing SSL inspection and has a requirement to support certificate pinning for a critical business application. The application uses a hardcoded certificate. The NGFW is configured to decrypt all traffic. What is the best way to handle this application?

    Select an answer first
  4. 29expert · hard

    A company has a Cisco NGFW that is integrated with Active Directory for user identity. However, some users work remotely and connect via VPN, and their traffic appears to come from the VPN concentrator's IP address. The security team wants to enforce user-based policies for these remote users. What is the best way to achieve this?

    Select an answer first
  5. 30expert · hard

    A security administrator is troubleshooting why a specific application is not being identified by AVC on the Cisco NGFW. The application uses TLS encryption and is known to use a custom protocol. The NGFW has the latest AVC updates. What is the most likely reason for the failure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.