
CCIE Security
Domain 3Objective 1
3.1 Device Hardening Techniques and Control Plane Protection Methods CCIE-SECURITY Practice Questions (Page 4)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
15%of the exam
Questions 16–20
- 16
Which global configuration command disables IP source routing on a Cisco IOS router?
Select an answer first - 17
A network team notices that the CPU of the core router spikes to 95% during a distributed denial-of-service (DDoS) attack, causing BGP sessions to flap. The team wants to ensure that routing protocol traffic is always processed while limiting the impact of attack traffic. What should they implement?
Select an answer first - 18
A security auditor is reviewing the configuration of a router and finds that IP source routing is enabled. The auditor also notes that the router has an iACL that permits traffic from a specific partner network. What is the risk of having IP source routing enabled in this scenario?
Select an answer first - 19
After configuring CoPP, the network team notices that OSPF neighbor adjacencies are flapping. They suspect that CoPP is dropping OSPF hello packets. Which command should they use to verify whether OSPF packets are being dropped by CoPP?
Select an answer first - 20
A network administrator is tasked with protecting the management plane of all network devices. They plan to implement iACLs. What is a key design consideration when creating the iACL?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.