
CCIE Security
Domain 1Objective 7
1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 5)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
10concepts
20%of the exam
Questions 21–25
- 21
A large e-commerce site is hit by a flood of UDP packets from thousands of different source IPs, saturating the uplink. The attack traffic is mostly large, fixed-size packets. The site's existing IPS is not dropping the traffic because it is stateless and the volume is overwhelming. What is the most effective immediate mitigation to preserve availability?
Select an answer first - 22
A security analyst is monitoring network traffic and notices a host sending DNS queries for a domain that is known to be a botnet command-and-control (C2) domain. The host is also communicating with other internal hosts on unusual ports. What is the best action to disrupt the botnet activity?
Select an answer first - 23
A company's web application is suffering from an attack that causes high CPU usage on the application servers. The attack traffic appears to be legitimate HTTP GET requests for a specific resource, but they are sent at a very high rate from a distributed set of IPs. The requests are not malformed and do not match any known signature. The company has a load balancer and an IPS. What is the most effective mitigation strategy?
Select an answer first - 24
A network security team is troubleshooting why their IPS is not detecting a known exploit. The exploit is delivered over HTTP, but the payload is split across multiple packets and the URL is encoded with %2e%2e (dot-dot) to represent directory traversal. The IPS has TCP reassembly enabled but still no alert. What is the most likely reason?
Select an answer first - 25
A security administrator is investigating a series of successful attacks on internal servers. The attacks appear to originate from internal IP addresses, but the administrator suspects spoofing. The network uses DHCP for IP assignment and has no authentication on the wired ports. Which combination of measures would best prevent IP spoofing and ARP poisoning?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.