Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 4

5.4 Cloud Security CCIE-SECURITY Practice Questions (Page 10)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)

60questions here
12free pages
10concepts
20%of the exam

Questions 46–50

  1. 46expert · hard

    An administrator has applied a DNS policy to block a specific malicious domain, but users are still able to access it. The VA is correctly configured and DNS proxy forwarding is working. The administrator has verified that the policy is active in Umbrella. What is the most likely cause of the issue?

    Select an answer first
  2. 47expert · hard

    A company wants to implement Remote Browser Isolation for all users, but they are concerned about the performance impact on web applications that require file downloads. The security team wants to ensure that file downloads are not blocked or degraded. What should the administrator configure in the RBI policy?

    Select an answer first
  3. 48expert · hard

    An organization has implemented RBI for its executive team, but the executives are complaining that some websites are not working correctly because of isolation. The administrator wants to allow those specific websites to be accessed directly while still isolating high-risk categories. What is the best approach?

    Select an answer first
  4. 49expert · hard

    A company is using Umbrella's CASB to control access to cloud applications. They have discovered that employees are using a new unsanctioned file-sharing service that is not yet in Umbrella's application catalog. The security team wants to block this service immediately. What should the administrator do?

    Select an answer first
  5. 50expert · hard · select all that apply

    A company wants to implement CASB policies to enforce threat protection and data loss prevention for cloud applications. They have both sanctioned and unsanctioned applications. The security team wants to ensure that sensitive data is not exfiltrated via any cloud service. Which of the following actions should the administrator take? (Select all that apply.)

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.