
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 6)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 26–30
- 26
An administrator is troubleshooting a NAT issue on an ASA in routed mode. The administrator has configured NAT and needs to verify that the translation is working. Which command should be used to see the active translations?
Select an answer first - 27
A small branch office has a single ASA firewall that needs to enforce a simple security policy for all traffic. The administrator wants the simplest configuration and management model, with one configuration file and one set of policies. Which mode should be used?
Select an answer first - 28
A service provider wants to offer firewall services to multiple customers using a single ASA appliance. Each customer must have its own independent security policy, but the provider wants to manage all customers on one device to save costs. Which mode should be used?
Select an answer first - 29
An enterprise is deploying a high-end FTD appliance to serve two different business units. Each business unit requires its own firewall instance with separate management and resource allocation, and they must be completely isolated from each other. Which mode should be used?
Select an answer first - 30
A network architect is designing a new firewall deployment for a data center. The firewall must be inserted into an existing VLAN without changing the IP addressing of the servers. The architect also needs to apply access control policies between the servers and the rest of the network. Which deployment mode should be chosen?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.