Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 7

1.7 Detect and Mitigate Common Types of Attacks CCIE-SECURITY Practice Questions (Page 9)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
10concepts
20%of the exam

Questions 41–45

  1. 41application · medium

    A large e-commerce site is experiencing intermittent outages during peak hours. Traffic analysis shows a massive influx of UDP packets to random ports on the server, consuming all available bandwidth. The attack traffic originates from many different source IPs, making it difficult to block with simple ACLs. Which mitigation strategy would be MOST effective to stop the bandwidth exhaustion while minimizing impact to legitimate users?

    Select an answer first
  2. 42application · medium

    A network security team is deploying a new IPS in-line. They want to ensure that the IPS can detect attacks that use IP fragmentation to evade signature matching. What is the BEST configuration to achieve this?

    Select an answer first
  3. 43application · medium

    A security administrator is setting up a remote access VPN for employees. The administrator wants to prevent session hijacking attacks where an attacker could steal a user's session token and impersonate them. Which measure is MOST effective?

    Select an answer first
  4. 44application · medium

    A web application is suffering from an application-layer DDoS attack where the attacker sends many HTTP GET requests for a specific resource that requires heavy database queries. The requests appear to come from legitimate browsers. Which mitigation is MOST appropriate?

    Select an answer first
  5. 45expert · hard

    A company has a network with multiple VLANs. The security team has received reports of users being redirected to malicious websites. After investigation, they find that the DNS responses are being spoofed. The network uses DHCP for IP assignment. Which combination of measures would BEST prevent DNS spoofing in this environment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.