
CCIE Security
Domain 3Objective 1
3.1 Device Hardening Techniques and Control Plane Protection Methods CCIE-SECURITY Practice Questions (Page 6)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
15%of the exam
Questions 26–30
- 26
A network engineer is designing CoPP for a router that is experiencing frequent DDoS attacks. The engineer wants to ensure that the router's CPU is protected, but also wants to maintain the ability to troubleshoot by allowing ICMP echo requests from a specific network operations center (NOC). Which CoPP configuration best meets these requirements?
Select an answer first - 27
A security consultant is reviewing a router's configuration and finds that IP source routing is enabled. The router also has an iACL that permits traffic from a specific partner network to access a management interface. The consultant is concerned about the combination of these two settings. What is the most significant risk?
Select an answer first - 28
A security engineer is configuring CoPP on a new edge router. They have created a class map that matches SSH, SNMP, and BGP traffic. What is the next step to apply the policy?
Select an answer first - 29
A network architect is designing a defense-in-depth strategy for the management plane of network devices. They plan to use both iACLs and CoPP. What is the primary advantage of using iACLs in addition to CoPP?
Select an answer first - 30
After implementing CoPP on a router, the network team wants to confirm that the policy is working and not dropping legitimate control plane traffic. Which command should they use to check the number of packets dropped by each class?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.