
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 7)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 31–35
- 31
An administrator has configured an ASA in routed mode and needs to verify that the firewall is correctly routing traffic between its interfaces. Which command should be used to check the routing table?
Select an answer first - 32
An administrator has configured an FTD in transparent mode and wants to verify that traffic is being bridged correctly between two interfaces. Which command or tool should be used?
Select an answer first - 33
A security administrator is managing an ASA in multi-context mode. The administrator needs to add a new context for a new customer. Which command should be used to create the context?
Select an answer first - 34
A service provider is deploying a new firewall for a customer that has a flat Layer 2 network segment between two routers. The customer insists that the firewall must not participate in routing or require any IP address changes on the existing routers. The firewall must enforce access control between the two sides. Which deployment mode should the engineer choose?
Select an answer first - 35
A telecom provider is deploying a Cisco Firepower 4100 series device to host firewall services for multiple enterprise customers. Each customer requires a separate firewall instance with its own management IP, separate software upgrade schedule, and dedicated CPU/memory resources. Which deployment mode is designed for this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.