
CCIE Security
Domain 1Objective 12
1.12 Correlation and Remediation Rules on Cisco FMC CCIE-SECURITY Practice Questions (Page 8)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
20%of the exam
Questions 36–38
- 36
A company is implementing automated threat response using FMC remediation rules. Which of the following are common remediation actions that can be performed by remediation rules? (Select all that apply.)
Select an answer first - 37
A security operations center (SOC) wants to automatically block a source IP when a correlation rule detects a port scan followed by a brute-force attempt within 5 minutes. How should the SOC configure FMC to achieve this?
Select an answer first - 38
After deploying a new correlation rule and associated remediation rule, the security team finds that the remediation rule is blocking legitimate users because the correlation rule triggers too easily. What is the best first step to tune the rules and reduce false positives?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.