
CCIE Security
Domain 5Objective 4
5.4 Cloud Security CCIE-SECURITY Practice Questions (Page 11)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
10concepts
20%of the exam
Questions 51–55
- 51
A financial institution wants to implement DLP policies to prevent sensitive customer data from being transmitted via web applications. They have a requirement to allow certain data, such as account numbers, to be transmitted to a specific trusted application. The administrator needs to configure DLP to block sensitive data except for that application. What should the administrator do?
Select an answer first - 52
An administrator has deployed the Umbrella virtual appliance and configured DNS proxy forwarding. They notice that some internal domains are being incorrectly blocked by Umbrella's security categories. The administrator wants to allow these internal domains while still enforcing security policies for external domains. What should the administrator do?
Select an answer first - 53
An administrator has implemented a DLP policy to block credit card numbers in web traffic. They want to ensure that the policy is working and that incidents are being reported to the security team. They also want to receive real-time alerts when a DLP incident occurs. What should the administrator configure?
Select an answer first - 54
A security team wants to block access to known malware domains and enforce security categories for all users in the marketing department. They have already deployed the Umbrella virtual appliance and configured DNS proxy forwarding. What is the next step to enforce the policy?
Select an answer first - 55
After applying a new DNS policy to block a list of malicious domains, the administrator wants to verify that the policy is actually being enforced for a specific user. What should the administrator use to confirm that the user's DNS queries are being blocked?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.