
CCIE Security
Domain 3Objective 3
3.3 Data Plane Protection Techniques CCIE-SECURITY Practice Questions (Page 5)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
15%of the exam
Questions 21–25
- 21
A network engineer is configuring CoPP on a router that carries both OSPF and BGP. The engineer wants to ensure that OSPF hellos are never dropped, but BGP updates can be rate-limited if necessary. Which policy-map configuration best achieves this?
Select an answer first - 22
A service provider is implementing RTBH to mitigate DDoS attacks. They have multiple customers and want to allow customers to trigger blackholing for their own IPs, but only for prefixes they own. The provider uses BGP communities. Which configuration is the most secure and scalable?
Select an answer first - 23
A network engineer is configuring uRPF on a router that has a default route pointing to an ISP. The router also has a directly connected network. The engineer wants to use strict uRPF but is concerned about dropping traffic from the directly connected network if the default route is used. What should the engineer do?
Select an answer first - 24
A network administrator is designing QoS to protect the control plane of a router that receives both legitimate management traffic (SSH) and potential DoS traffic. The administrator wants to ensure that SSH is always available, but also wants to limit the impact of a DoS attack. Which approach is most effective?
Select an answer first - 25
A network engineer is implementing RTBH using BGP. Which two configurations are required on the edge routers to ensure that blackhole routes are installed and traffic is dropped? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.