Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 7

1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 7)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 31–35

  1. 31expert · hard

    A security team is investigating a suspected man-in-the-middle attack on a corporate network. They notice that the ARP cache on several workstations has been modified, and the MAC address of the default gateway is incorrect. The network uses DHCP and has no port security. What is the best immediate action to stop the attack?

    Select an answer first
  2. 32application · medium

    A security analyst notices that an intrusion prevention system (IPS) is not alerting on a known exploit signature. The exploit uses a payload that is split across multiple TCP segments, each smaller than the IPS's reassembly buffer. Which evasion technique is being used, and what countermeasure should be implemented?

    Select an answer first
  3. 33expert · hard

    A company's network is infected with a botnet that uses a domain generation algorithm (DGA) to create C2 domains. The security team has identified the malware and wants to disrupt the botnet. The team has access to the ISP's DNS sinkhole service. What is the most effective approach?

    Select an answer first
  4. 34application · medium

    A network administrator is configuring a new branch office router. The router connects to the ISP and also to the internal LAN. To prevent spoofing attacks from the internal network, which configuration should be applied on the router's internal interface?

    Select an answer first
  5. 35application · medium

    A user on the corporate network reports that when they visit a banking website, the page shows a warning about an invalid certificate. The network team suspects a man-in-the-middle attack. Which technique is likely being used, and what should be implemented to prevent it?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.