Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 7

1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 6)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 26–30

  1. 26expert · hard

    A company is deploying a new wireless network for guests. The security team is concerned about man-in-the-middle attacks, particularly SSL stripping and ARP poisoning. The wireless network is isolated from the corporate network, but guests need internet access. What is the most effective way to mitigate these attacks?

    Select an answer first
  2. 27expert · hard

    A security operations center (SOC) is analyzing a botnet infection. The botnet uses a peer-to-peer (P2P) communication model, and the infected hosts are also generating DNS queries for a domain that is used as a fallback C2. The SOC wants to disrupt the botnet without losing visibility. Which strategy is most effective?

    Select an answer first
  3. 28expert · hard

    A company is experiencing a DDoS attack that is a mix of UDP flood and fragmented ICMP packets. The attack is saturating the internet link. The company has a scrubbing service available from their ISP. What is the best approach to mitigate this attack?

    Select an answer first
  4. 29expert · hard

    A security analyst is reviewing IDS logs and notices that an attacker is sending HTTP requests with the payload split across multiple packets and using chunked transfer encoding. The IDS is configured to reassemble TCP streams but is still missing the attack. What is the most likely reason?

    Select an answer first
  5. 30expert · hard

    A network administrator is configuring a new DMZ for public-facing servers. The servers need to be accessible from the internet, but the administrator wants to prevent IP spoofing and DNS spoofing. Which set of measures should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.