Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 2

1.2 Firewall Features on Cisco ASA and FTD CCIE-SECURITY Practice Questions (Page 8)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
12concepts
20%of the exam

Questions 36–40

  1. 36expert · hard

    An engineer is troubleshooting asymmetric traffic flow through an ASA. The inside host 10.1.1.10 initiates a connection to an outside server 203.0.113.5. The ASA has a static NAT for the inside host (10.1.1.10 -> 198.51.100.10) and a static NAT for the outside server (203.0.113.5 -> 172.16.1.5) to allow return traffic. The connection fails. The engineer suspects the NAT configuration is not handling the return traffic correctly. Which NAT type should be used to ensure bidirectional translation for both source and destination?

    Select an answer first
  2. 37expert · hard

    An engineer is configuring NAT on an FTD device. They have a requirement to translate both the source and destination addresses for a specific traffic flow between two internal networks. The source network 10.0.0.0/24 should be translated to 192.168.1.0/24, and the destination network 172.16.0.0/16 should be translated to 10.10.0.0/16. Which NAT type should be used?

    Select an answer first
  3. 38application · medium

    A security administrator is configuring an ASA to inspect FTP traffic. The requirement is to enforce strict compliance with FTP RFC standards and to block FTP commands that are not allowed by corporate policy. The administrator has already created an inspection policy map. What additional configuration is needed to enforce the FTP command filtering?

    Select an answer first
  4. 39expert · hard

    A large enterprise uses an ASA to inspect HTTP traffic. They have a requirement to block HTTP requests that contain certain URL patterns and to enforce a maximum URI length. They also need to allow HTTP traffic only from specific source networks. The administrator has created an HTTP inspection policy map. Which of the following configurations is necessary to enforce the URL filtering and URI length limit?

    Select an answer first
  5. 40application · medium

    An organization is deploying FTD in a multi-tenant environment. They need to group interfaces into different security zones to apply distinct security policies. The administrator has created two zones: 'Inside' and 'Outside'. Which configuration step is required to enforce zone-based policies?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.