
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 10)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 46–50
- 46
An engineer has configured an ASA in transparent mode with a bridge group containing Gi0/0 and Gi0/1. The engineer wants to verify that the bridge group is correctly forwarding traffic. Which command should be used to verify the bridge group status?
Select an answer first - 47
A managed security service provider (MSSP) is deploying a Cisco Firepower 9300 for multiple customers. Each customer requires a completely independent firewall instance with its own management plane, separate software version, and dedicated resources. The MSSP needs to ensure that a failure in one customer's instance does not affect others. Which deployment mode should be used?
Select an answer first - 48
A network engineer is replacing a legacy router with a Cisco ASA in routed mode to provide firewall services between two subnets: 192.168.1.0/24 and 10.10.10.0/24. The ASA will be the default gateway for both subnets. Which configuration step is essential for the ASA to forward traffic between the two subnets?
Select an answer first - 49
A company wants to insert an ASA in transparent mode between two switches that carry multiple VLANs. The ASA must pass traffic for all VLANs without being the gateway for any of them. What is a required configuration on the ASA to achieve this?
Select an answer first - 50
A small business is deploying a single Cisco ASA for its internet edge. They have one inside interface and one outside interface, and they need a simple firewall with a single security policy. They do not anticipate needing to virtualize the firewall. Which deployment mode is the default and most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.