
CCIE Security
Domain 3Objective 1
3.1 Device Hardening Techniques and Control Plane Protection Methods CCIE-SECURITY Practice Questions (Page 7)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
8concepts
15%of the exam
Questions 31–35
- 31
A network administrator is reviewing security best practices for edge routers. They notice that IP source routing is enabled by default. What is the primary security concern with leaving IP source routing enabled?
Select an answer first - 32
A company's security policy requires that all routers and switches disable IP source routing to prevent packet redirection attacks. Which configuration command should be applied on Cisco IOS devices?
Select an answer first - 33
A network architect is designing security controls for a new data center. They want to prevent external attackers from sending traffic directly to the management interfaces of core switches and routers. Which technique should they implement?
Select an answer first - 34
A network engineer is designing an iACL to protect the management plane of a router. The router has a loopback interface with IP 10.0.0.1/32 used for management. The engineer wants to allow SSH from a management subnet 192.168.1.0/24 and deny all other traffic to the loopback. Which ACL configuration is correct?
Select an answer first - 35
A network team is implementing iACLs to protect their core infrastructure. They have two edge routers connecting to the internet. Where should the iACL be applied to be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.