
CCIE Security
Domain 3Objective 8
3.8 Cisco SAFE Model to Validate Network Security Design and to Identify Threats to Different PINs CCIE-SECURITY Practice Questions (Page 4)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
15%of the exam
Questions 16–20
- 16
A company is implementing a SAFE-based design with limited budget. They need to protect the campus, branch, and data center PINs. The campus has many users, the branch has a small number of users, and the data center hosts critical applications. Which capability should be prioritized to get the best security ROI?
Select an answer first - 17
A security architect is assessing the threat landscape for a multi-PIN network. The network includes a campus, a branch, a data center, and a cloud environment. Which threats are most relevant to the cloud PIN? (Select all that apply.)
Select an answer first - 18
A company has a network design that includes a data center with strong security controls, but the campus network has no segmentation and the branch has no security controls at all. The architect is using the SAFE model to validate the design. Which statement best describes the design's alignment with SAFE?
Select an answer first - 19
A network architect is designing a new branch office that will connect to the corporate data center via the internet. The architect wants to apply SAFE design principles. Which combination of principles and capabilities is most appropriate for this branch?
Select an answer first - 20
A security team is analyzing threats for a new cloud deployment. They are using the SAFE model to identify the most critical threats. Which threat should be considered the highest risk for the cloud PIN, and why?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.