Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 7

1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 10)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 46–50

  1. 46expert · hard · select all that apply

    A security analyst is investigating a potential botnet infection on a corporate workstation. The workstation is making periodic HTTPS connections to a known malicious domain. The analyst wants to confirm the botnet and disrupt its C2 channel without completely isolating the workstation. Select all that apply.

    Select an answer first
  2. 47expert · hard

    A company is experiencing a DDoS attack that is targeting their DNS infrastructure. The attack is a mix of volumetric UDP floods and DNS amplification attacks. The company has a limited budget and needs to maintain DNS availability for legitimate users. Which mitigation strategy provides the BEST balance of cost and effectiveness?

    Select an answer first
  3. 48expert · hard

    A security engineer is configuring an IPS to detect and prevent evasion techniques. The engineer notices that the IPS is missing attacks that use overlapping IP fragments, where the second fragment overwrites part of the first. The IPS is currently set to reassemble fragments in the order they arrive. What is the BEST configuration to prevent this evasion?

    Select an answer first
  4. 49expert · hard

    A network administrator is troubleshooting a MITM attack on a network. The administrator suspects ARP poisoning is occurring. The switches support DHCP snooping and Dynamic ARP Inspection (DAI). However, DAI is not enabled on all VLANs. Which additional measure would be MOST effective in detecting ARP poisoning on VLANs where DAI is not enabled?

    Select an answer first
  5. 50expert · hard · select all that apply

    A security team is analyzing network traffic and suspects that a botnet is using a peer-to-peer (P2P) C2 model, where bots communicate with each other rather than a central server. The team wants to disrupt the botnet. Which actions would be effective in disrupting a P2P botnet? Select all that apply.

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.