Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 7

1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 11)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 51–55

  1. 51expert · hard

    A company is implementing anti-spoofing measures on their network. They have a router that connects to the internet and a switch that connects to internal hosts. The internal hosts use DHCP. The company wants to prevent IP spoofing from internal hosts and also prevent ARP spoofing. Which set of configurations would achieve both goals?

    Select an answer first
  2. 52application · medium

    A security analyst notices that the intrusion prevention system (IPS) is not alerting on a known exploit signature, even though the exploit is being attempted. Upon reviewing packet captures, the analyst sees that the malicious payload is split across multiple TCP segments, with each segment smaller than the signature's pattern size. Which technique is being used to evade the IPS, and what is the BEST countermeasure?

    Select an answer first
  3. 53expert · hard

    A company is experiencing a DDoS attack that is a combination of a SYN flood and an HTTP flood. The SYN flood is consuming network resources, and the HTTP flood is overwhelming the web server. The company has a firewall and an IPS. Which mitigation strategy would be MOST effective in addressing both attack vectors?

    Select an answer first
  4. 54application · medium

    A security engineer is investigating a report that users on the corporate network are seeing browser warnings about invalid certificates when visiting an internal website. The engineer suspects an SSL stripping attack. Which additional observation would CONFIRM the attack, and what is the BEST prevention measure?

    Select an answer first
  5. 55application · medium

    A security operations center (SOC) is monitoring network traffic and notices a large number of internal hosts making periodic outbound connections to the same external IP address on port 443, but the traffic patterns are not typical of web browsing. The SOC suspects a botnet. Which action would BEST confirm the botnet and potentially disrupt its command-and-control (C2) channel?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.