
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 11)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 51–53
- 51
An engineer has configured an ASA in routed mode with two interfaces: Gi0/0 (inside, 192.168.1.1/24) and Gi0/1 (outside, 203.0.113.1/24). After configuration, the engineer wants to verify that the ASA is correctly routing between the two interfaces. Which command should be used?
Select an answer first - 52
A network architect is designing a firewall deployment for a data center. The firewall must be inserted between two core switches that are already configured with HSRP for gateway redundancy. The architect wants to avoid any changes to the existing IP addressing or routing. Which deployment mode should be selected?
Select an answer first - 53
A university is deploying a single ASA to secure its administrative and student networks. They want to maintain separate security policies for each network but share the same hardware. The administrator needs to manage each network's policy independently. Which mode should be configured?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.