
CCIE Security
Domain 5Objective 2
5.2 Detect, Analyze, and Mitigate Malware Incidents CCIE-SECURITY Practice Questions (Page 8)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
20%of the exam
Questions 36–40
- 36
A malware incident is confirmed on a server that stores sensitive data. The incident response team is considering whether to disconnect the server from the network or keep it online for monitoring. What is the best course of action?
Select an answer first - 37
A company wants to reduce the risk of malware spreading from the IT department to the OT (operational technology) network. The OT network controls critical infrastructure. Which mitigation strategy is most effective?
Select an answer first - 38
A SOC is investigating an alert about a suspicious outbound connection to an IP address. The IP is not on any blocklist, but the SOC wants to assess its reputation quickly. Which action is most appropriate?
Select an answer first - 39
A security analyst needs to analyze a suspicious document that was received via email. The analyst wants to determine if the document contains a malicious macro. Which analysis method is most appropriate?
Select an answer first - 40
During a malware campaign analysis, a security team identifies several IOCs. Which of the following are considered IOCs that should be documented? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.