Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 1

3.1 Device Hardening Techniques and Control Plane Protection Methods CCIE-SECURITY Practice Questions (Page 5)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
8concepts
15%of the exam

Questions 21–25

  1. 21expert · hard

    A network engineer is configuring CoPP on a router that carries both management traffic (SSH, SNMP) and routing protocols (BGP, OSPF). The engineer wants to ensure that routing protocol traffic is never dropped, even during an attack, while management traffic should be rate-limited. Which CoPP policy design is most appropriate?

    Select an answer first
  2. 22expert · hard

    A network team is implementing iACLs to protect their infrastructure. They have multiple edge routers and a core network. The iACL must allow BGP (TCP 179) from a specific peer, allow SSH from a management subnet, and deny all other traffic to infrastructure IPs. However, the team also needs to ensure that the iACL does not break OSPF adjacencies. What should they include in the iACL?

    Select an answer first
  3. 23expert · hard

    A security engineer is hardening a router that connects to multiple external partners. The router has an iACL that permits only specific partner IPs to access certain services. The engineer wants to disable IP source routing to prevent bypassing the iACL. However, one partner uses an application that relies on source routing for load balancing. What should the engineer do?

    Select an answer first
  4. 24expert · hard

    A network administrator has implemented CoPP on a router and is monitoring its performance. They notice that the 'show policy-map control-plane' output shows an increasing number of dropped packets in the class that matches SSH traffic. The administrator is concerned that legitimate SSH sessions are being dropped. What is the best course of action?

    Select an answer first
  5. 25expert · hard

    A network team is deploying iACLs across their enterprise. They have a mix of Cisco routers and switches. The team wants to verify that the iACL is actually blocking unwanted traffic to infrastructure devices. Which method is most effective for verification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.