
CCIE Security
Domain 1Objective 7
1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 8)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
10concepts
20%of the exam
Questions 36–40
- 36
A security analyst is investigating a series of compromised hosts that are sending outbound connections to the same IP address on port 443 at regular intervals. The traffic is encrypted and appears to be web traffic. What is the most likely explanation, and what action should be taken?
Select an answer first - 37
A web server is experiencing intermittent slowdowns. The logs show many incomplete TCP handshakes from a single source IP, with the server sending SYN-ACKs but never receiving the final ACK. This is consuming server resources. What type of attack is this, and what is the best mitigation?
Select an answer first - 38
An attacker is sending HTTP requests to a web server with the payload encoded in UTF-16 and using multiple slashes in the URL path. The intrusion detection system (IDS) is not generating alerts. Which evasion technique is being used, and what should be configured to detect it?
Select an answer first - 39
A network administrator is concerned about ARP spoofing on the access layer. The switches support DHCP snooping and Dynamic ARP Inspection (DAI). What is the correct configuration to prevent ARP spoofing?
Select an answer first - 40
A security engineer is configuring a remote access VPN for employees. The goal is to prevent session hijacking and man-in-the-middle attacks. Which configuration should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.