
CCIE Security
Domain 1Objective 12
1.12 Correlation and Remediation Rules on Cisco FMC CCIE-SECURITY Practice Questions (Page 4)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
20%of the exam
Questions 16–20
- 16
Which of the following is a valid action that can be configured for a correlation rule on Cisco FMC?
Select an answer first - 17
What is the purpose of configuring an action like 'drop packets' in a correlation rule?
Select an answer first - 18
What is the primary purpose of a remediation rule on Cisco FMC?
Select an answer first - 19
A security analyst at a large enterprise notices that the FMC event viewer is flooded with thousands of individual intrusion events from multiple sensors, making it difficult to identify a coordinated attack. The analyst wants to reduce noise and get a single alert when a specific pattern of events occurs across the network within a short time window. What should the analyst configure in FMC?
Select an answer first - 20
A network team wants to create a correlation rule that detects a distributed denial-of-service (DDoS) attack by aggregating events from multiple sensors. The rule should trigger when any single source IP sends more than 1,000 packets to a single destination within 1 minute. What is the most efficient way to define this rule in FMC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.