Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 1

1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 5)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
7concepts
20%of the exam

Questions 21–25

  1. 21expert · medium

    An administrator is configuring a new FTD in routed mode. The administrator needs to verify that the firewall is correctly performing NAT for internal users. Which command should be used?

    Select an answer first
  2. 22expert · hard

    A security administrator is managing an ASA in multi-context mode. The administrator needs to change the deployment mode from multi-context to single context. What is the correct procedure?

    Select an answer first
  3. 23expert · hard

    An administrator is deploying an FTD in multi-instance mode. The administrator needs to allocate specific CPU and memory resources to each instance. Which command should be used?

    Select an answer first
  4. 24expert · hard

    A network engineer is evaluating whether to use routed or transparent mode for a new firewall deployment. The firewall will be placed between two routers that are already configured with a routing protocol. The engineer wants to minimize the impact on the existing routing design. Which mode should be chosen?

    Select an answer first
  5. 25application · easy

    A network administrator needs to insert an FTD device into an existing network segment without changing the IP addressing scheme. The device should bridge traffic between two switch ports and apply security policies without performing any routing. Which deployment mode should be selected?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.