
CCIE Security
Domain 1Objective 12
1.12 Correlation and Remediation Rules on Cisco FMC CCIE-SECURITY Practice Questions (Page 7)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
20%of the exam
Questions 31–35
- 31
A security team wants to automate the response to a detected ransomware infection. When a correlation rule detects the infection, the FMC should automatically isolate the infected host from the network. Which remediation action should be configured?
Select an answer first - 32
An organization wants to detect a potential data exfiltration attempt. The security team creates a correlation rule that triggers when a host sends more than 100 MB of data to an external IP within 10 minutes. After deploying the rule, they notice it fires too frequently due to legitimate large file transfers. What should they do to reduce false positives while still detecting real exfiltration?
Select an answer first - 33
A security engineer is configuring a correlation rule in FMC to respond to a detected malware outbreak. The rule should automatically block the infected host's IP address on the network. What action should the engineer configure in the correlation rule to achieve this?
Select an answer first - 34
A company wants to automate the response to a detected brute-force attack. When a correlation rule detects the attack, the FMC should automatically block the attacking IP address on the ASA firewall for 24 hours. What should the administrator configure?
Select an answer first - 35
A security analyst needs to configure a remediation rule in FMC to quarantine a host that has been identified as infected by a correlation rule. The quarantine should be implemented by blocking the host's IP on the network. What must the analyst specify in the remediation rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.