
CCIE Security
Domain 1Objective 2
1.2 Firewall Features on Cisco ASA and FTD CCIE-SECURITY Practice Questions (Page 7)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
20%of the exam
Questions 31–35
- 31
An organization is deploying FTD and wants to use traffic zones to simplify policy management. They have multiple interfaces for different departments (HR, Finance, Engineering) and want to apply the same security policy to all of them. Which approach is most efficient?
Select an answer first - 32
An engineer is configuring PBR on an FTD to send VoIP traffic from a specific subnet to a WAN optimizer. The route map is configured to match the source subnet and set the next hop to the WAN optimizer. However, the engineer notices that the VoIP traffic is not being redirected. The engineer has verified that the route map is correct and applied to the ingress interface. What else should be checked?
Select an answer first - 33
A company wants to redirect all traffic from the DMZ to a FirePOWER module for advanced threat inspection. The FirePOWER module is connected to a separate interface on the ASA. Which redirection method is most appropriate?
Select an answer first - 34
An organization is implementing identity firewall on their ASA. They have integrated with Active Directory and are using user-based policies. However, they notice that some users are being denied access even though they are members of the allowed group. The administrator suspects that the user-to-IP mapping is not being updated correctly. What is the most likely cause?
Select an answer first - 35
A security administrator is creating an inspection policy for HTTP traffic on an ASA. The policy must enforce the following: block requests with certain URL patterns, limit the maximum URI length, and allow only specific HTTP methods. Which of the following actions should be included in the HTTP inspection policy map? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.