
CCIE Security
Domain 1Objective 2
1.2 Firewall Features on Cisco ASA and FTD CCIE-SECURITY Practice Questions (Page 5)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
20%of the exam
Questions 21–25
- 21
On Cisco ASA/FTD, which command is used to enable the HTTP inspection engine globally?
Select an answer first - 22
Which advanced inspection option can be configured in an inspection policy to control the maximum size of a DNS response packet?
Select an answer first - 23
What is the purpose of applying an inspection policy to a specific interface on Cisco ASA/FTD?
Select an answer first - 24
What is a traffic zone on Cisco ASA/FTD?
Select an answer first - 25
A company is deploying a new FTD device at the internet edge. They have a single public IP address and need to allow internal users to access the internet while also hosting a web server on the DMZ. The web server must be reachable from the internet on port 443. The security team wants to ensure that DNS inspection is applied to all outbound traffic. Which NAT configuration should be used to meet these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.