
CCIE Security
Domain 1Objective 5
1.5 Cisco NGIPS Deployment Modes CCIE-SECURITY Practice Questions (Page 5)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
3concepts
20%of the exam
Questions 21–25
- 21
A security architect is designing a network for a bank. They need to block malware and also perform deep packet inspection on encrypted traffic. The NGIPS supports SSL decryption, but decryption requires significant processing. The bank has a high-availability requirement. What is the best deployment strategy?
Select an answer first - 22
A university is deploying a Cisco NGIPS to monitor research network traffic. They have a requirement to capture all traffic for compliance, but the network uses a mix of SPAN and TAP. They have noticed that some traffic is not being seen by the NGIPS because the SPAN port is not configured correctly. What is the most likely cause and solution?
Select an answer first - 23
A large enterprise is planning to deploy a Cisco NGIPS to protect its core network. The security team has identified the following requirements: (1) block known malicious traffic, (2) ensure no single point of failure causes downtime, (3) maintain visibility even if the NGIPS fails. Which of the following actions would satisfy these requirements? Select all that apply.
Select an answer first - 24
A network administrator is troubleshooting a Cisco NGIPS that is deployed in passive mode using a TAP. The NGIPS is not detecting any traffic, even though the TAP is connected to the link. The TAP has two output ports, and the NGIPS has two monitoring interfaces. What is the most likely issue?
Select an answer first - 25
A university network team wants to monitor traffic on a high-utilization backbone link for threat detection without risking any impact on performance. They have a Cisco NGIPS and are deciding between a SPAN port and a network TAP. The link is already near capacity, and the switch has limited resources. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.