
CCIE Security
Domain 1Objective 1
1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 8)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
20%of the exam
Questions 36–40
- 36
A company is deploying an ASA in routed mode as the gateway for a new branch office. The branch has two subnets: 192.168.10.0/24 and 192.168.20.0/24. The ASA has three interfaces: Gi0/0 (outside), Gi0/1 (inside for 192.168.10.0/24), and Gi0/2 (DMZ for 192.168.20.0/24). The engineer wants to ensure that traffic from the inside can reach the DMZ and the outside, but the DMZ cannot initiate traffic to the inside. What is the correct security-level configuration?
Select an answer first - 37
An engineer is troubleshooting a transparent mode ASA that is not passing traffic between two VLANs. The ASA has a bridge group with Gi0/0 and Gi0/1, and a management IP of 10.10.10.2/24. The engineer notices that the ASA can ping the management IP from the network, but traffic between hosts on the two VLANs is not forwarded. What is the most likely cause?
Select an answer first - 38
A security architect is evaluating deployment modes for a new Cisco Firepower 9300. The requirement is to support multiple customers, each needing a separate firewall instance with its own management plane and the ability to run different software versions. However, the architect also needs to maximize the number of customers per appliance while keeping hardware costs low. Which approach should be recommended?
Select an answer first - 39
An engineer is configuring an ASA in routed mode for a new site. The ASA will be the gateway for the inside network (192.168.1.0/24) and will connect to the internet via a service provider. The engineer has assigned IP addresses to the interfaces and configured a default route to the provider. However, inside hosts cannot reach the internet. The engineer verifies that the ASA can ping the provider's gateway, but inside hosts cannot. What is the most likely missing configuration?
Select an answer first - 40
A network administrator is planning to migrate an existing ASA from single context mode to multi-context mode. The administrator needs to ensure that the migration is successful and that existing configurations are preserved. Which of the following are required steps or considerations for this migration? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.