Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 3

3.3 Data Plane Protection Techniques CCIE-SECURITY Practice Questions (Page 7)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
9concepts
15%of the exam

Questions 31–35

  1. 31expert · hard

    A network engineer is configuring CoPP on a router that has both a management interface and a data plane interface. The engineer wants to ensure that SSH management traffic is always allowed, but also wants to protect the control plane from ICMP floods. Which configuration is best?

    Select an answer first
  2. 32application · medium

    A financial institution wants to ensure that latency-sensitive trading traffic is prioritized over bulk data transfers on their WAN edge routers. They also want to protect the control plane from being overwhelmed by excessive traffic. Which QoS strategy should be implemented?

    Select an answer first
  3. 33application · medium

    A company's internet edge router is experiencing intermittent DoS attacks that cause link saturation. The security team wants to mitigate the impact by limiting the rate of certain traffic types without dropping all traffic. They also need to ensure that legitimate business-critical traffic is not affected. Which QoS mechanism should be applied?

    Select an answer first
  4. 34application · medium

    A network administrator is configuring control plane protection on a router that receives BGP, OSPF, and SSH traffic. The router has been experiencing high CPU usage due to excessive SSH connection attempts. The administrator wants to limit SSH traffic without affecting routing protocols. Which configuration should be used?

    Select an answer first
  5. 35application · medium

    A large enterprise is facing a volumetric DDoS attack targeting a specific server IP. The attack is saturating the internet link. The security team wants to drop all traffic to the victim IP at the edge routers while minimizing impact on other traffic. Which technique should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.