Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 12

1.12 Correlation and Remediation Rules on Cisco FMC CCIE-SECURITY Practice Questions (Page 5)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
9concepts
20%of the exam

Questions 21–25

  1. 21expert · hard

    A large enterprise has multiple FMC-managed sensors. The security team wants to create a correlation rule that detects a multi-stage attack: first, a port scan from an external IP, followed by a brute-force attempt on a specific server within 10 minutes. The rule should only trigger if the same source IP is involved in both stages. The team also wants to minimize false positives from legitimate scanning tools. What is the best approach?

    Select an answer first
  2. 22expert · hard

    A security architect is designing an automated response system. A correlation rule detects a compromised host attempting to communicate with a command-and-control (C2) server. The architect wants to block the host's IP on the firewall and also quarantine the host via ISE. However, the remediation rule can only perform one action per trigger. What should the architect do to achieve both actions?

    Select an answer first
  3. 23expert · hard

    A company uses FMC with multiple remediation modules, including ASA, ISE, and a third-party SIEM. The security team wants to ensure that when a correlation rule triggers, the remediation rule blocks the IP on the ASA and sends a notification to the SIEM. However, the SIEM module is not available in the FMC's remediation module list. What is the best alternative to achieve the SIEM notification?

    Select an answer first
  4. 24expert · hard

    A security administrator is configuring a remediation rule to block a malicious IP on an ASA firewall. The rule will be triggered by a correlation rule that detects a high rate of intrusion events. The administrator wants to ensure that the block is temporary and automatically expires after 1 hour to avoid permanently blocking a potentially legitimate IP. What should the administrator configure?

    Select an answer first
  5. 25expert · hard

    A company has a remediation rule that blocks a source IP on the ASA when a correlation rule detects a brute-force attack. However, the attacker is using a botnet with rotating IP addresses, so the block is ineffective. The security team wants to improve the response. What is the most effective remediation action to add?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.