Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 2

1.2 Firewall Features on Cisco ASA and FTD CCIE-SECURITY Practice Questions (Page 6)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
12concepts
20%of the exam

Questions 26–30

  1. 26expert · hard

    An administrator has configured PBR to redirect traffic to a FirePOWER module for inspection. The redirection is working, but the administrator notices that some traffic is not being inspected. The traffic that is not inspected is traffic that is generated by the ASA itself (e.g., management traffic). What is the likely reason for this?

    Select an answer first
  2. 27application · medium

    A company wants to enforce access control based on user identity rather than just IP addresses. They have an Active Directory environment and want to allow or deny traffic based on user group membership. Which feature should be configured on the ASA?

    Select an answer first
  3. 28application · medium

    An administrator is configuring identity firewall on an FTD device. They have integrated with Active Directory and want to enforce a policy that allows only members of the 'Finance' group to access a specific server. Which configuration step is essential?

    Select an answer first
  4. 29expert · hard

    A network engineer is troubleshooting a NAT issue on an ASA. Inside hosts are unable to access the internet. The configuration includes a dynamic PAT rule for the inside interface and a static NAT for a DMZ server. The engineer suspects that the NAT order of operations is causing the issue. Which of the following is the correct order of NAT operations on the ASA?

    Select an answer first
  5. 30application · medium

    A security administrator needs to inspect DNS traffic to prevent DNS tunneling. They have an ASA and want to enforce DNS message length limits and block certain DNS query types. Which configuration is required?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.