
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 4)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 16–20
- 16
An administrator is working with an FTD device in multi-instance mode. The administrator needs to verify the resource allocation for each instance. Which command should be used?
Select an answer first - 17
A managed security service provider (MSSP) is using an ASA in multi-context mode to serve multiple customers. One customer requires a feature that is not supported in multi-context mode, such as VPN remote access. The MSSP needs to provide this service without purchasing additional hardware. What should the MSSP do?
Select an answer first - 18
A large enterprise is deploying a new FTD appliance to serve two separate departments. Each department requires its own firewall instance with separate management and resource allocation. The enterprise also wants to minimize hardware costs. Which mode should be used?
Select an answer first - 19
An administrator is troubleshooting a connectivity issue on an ASA in transparent mode. The administrator suspects that the firewall is not forwarding traffic correctly. Which command should be used to verify the bridge group configuration?
Select an answer first - 20
A network architect is designing a firewall deployment for a multi-tenant building. Each tenant needs its own security policy, and the firewall must be inserted into the existing network without changing the IP addressing scheme. The architect also needs to provide NAT for some tenants. Which combination of modes should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.