
CCIE Security
Domain 3Objective 3
3.3 Data Plane Protection Techniques CCIE-SECURITY Practice Questions (Page 4)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
15%of the exam
Questions 16–20
- 16
What is the primary purpose of QoS classification and marking in protecting network infrastructure?
Select an answer first - 17
Which QoS field is commonly used to mark packets for classification in modern IP networks?
Select an answer first - 18
What is the difference between QoS policing and shaping?
Select an answer first - 19
A service provider is experiencing spoofed-source DDoS attacks targeting a customer edge router. The router has two upstream links to different ISPs, and asymmetric routing is common. The team needs to drop packets with spoofed source addresses while avoiding disruption to legitimate traffic. Which uRPF configuration should be applied on the customer-facing interfaces?
Select an answer first - 20
A network administrator is designing QoS policies to protect the network infrastructure from DoS attacks. Which two mechanisms are commonly used together to identify and control traffic rates? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.