Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 1

1.1 Deployment Modes on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 9)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
7concepts
20%of the exam

Questions 41–45

  1. 41expert · hard

    A service provider is deploying a Firepower 9300 with multi-instance mode to host firewall instances for multiple customers. One customer requires a high-availability pair, but the provider only has one physical appliance. The provider wants to use multi-instance to create two instances on the same appliance for the customer's HA pair. Is this a valid design?

    Select an answer first
  2. 42application · medium

    A company is deploying a new ASA in routed mode to segment its corporate network from a partner network. The ASA will have two interfaces: Gi0/0 (corporate, 10.0.0.1/24) and Gi0/1 (partner, 192.168.1.1/24). The security policy requires that corporate hosts can initiate connections to the partner network, but partner hosts cannot initiate connections to the corporate network. What is the simplest way to achieve this using security levels?

    Select an answer first
  3. 43application · medium

    A hospital is deploying an ASA in transparent mode between its existing core switch and a new medical device network. The medical devices are on the same IP subnet as the hospital's main network, and the hospital does not want to change the IP addressing. The ASA must filter traffic between the two segments. What is the primary advantage of using transparent mode in this scenario?

    Select an answer first
  4. 44application · easy

    A small office is deploying a Cisco ASA for internet access. They have a single inside interface and a single outside interface. The administrator wants to keep the configuration simple and does not need to virtualize the firewall. Which deployment mode should be used, and what is a characteristic of that mode?

    Select an answer first
  5. 45application · medium

    A large enterprise wants to consolidate multiple firewalls from different business units into a single ASA appliance to reduce hardware costs. Each business unit requires its own routing table, NAT policies, and access control lists, and they must not be able to see or affect each other's configurations. Which deployment mode best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.