
CCIE Security
Domain 3Objective 3
3.3 Data Plane Protection Techniques CCIE-SECURITY Practice Questions (Page 8)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
15%of the exam
Questions 36–38
- 36
A service provider wants to implement RTBH to mitigate DDoS attacks. They plan to use BGP communities to trigger blackholing. Which configuration step is essential for the RTBH trigger router?
Select an answer first - 37
An enterprise has implemented RTBH using BGP. After a DDoS attack, the team advertises a blackhole route for the victim IP. However, they notice that the attack traffic is still reaching the victim. What is the most likely reason?
Select an answer first - 38
A network engineer is troubleshooting a uRPF issue on a router where legitimate traffic is being dropped. The router has multiple interfaces and uses OSPF. The engineer suspects that the FIB does not have a route for some source prefixes. Which command should be used to verify the FIB entries for those source prefixes?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.