
CCIE Security
Domain 1Objective 6
1.6 Cisco NGFW Features CCIE-SECURITY Practice Questions (Page 7)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
11concepts
20%of the exam
Questions 31–35
- 31
A company wants to enforce a policy that blocks access to social media applications for all users in the 'Marketing' group, but allows access for the 'Executives' group. The NGFW is integrated with Active Directory. What is the most efficient way to implement this policy?
Select an answer first - 32
A multinational company wants to block all traffic from countries where it has no business operations, except for a few specific partner IP addresses in those countries. The NGFW uses the geolocation database. What is the best way to implement this?
Select an answer first - 33
An organization wants to ensure that video streaming applications do not consume excessive bandwidth during business hours, but they should still be accessible. The NGFW supports AVC. What should the administrator configure?
Select an answer first - 34
A security administrator needs to inspect SSL traffic to detect data exfiltration, but the organization's privacy policy prohibits decrypting traffic for employees' personal webmail. What is the best approach?
Select an answer first - 35
A company is implementing SSL inspection and wants to ensure that internal clients do not see certificate warnings when accessing internal applications. The NGFW will generate a certificate for each internal site. What should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.