
CCIE Security
Domain 1Objective 2
1.2 Firewall Features on Cisco ASA and FTD CCIE-SECURITY Practice Questions (Page 9)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
20%of the exam
Questions 41–44
- 41
A network engineer is configuring zone-based firewall policies on an ASA. They have three zones: Inside, Outside, and DMZ. They want to allow HTTP traffic from Inside to DMZ, but block all other traffic from Inside to DMZ. They also want to inspect HTTP traffic. Which configuration approach is correct?
Select an answer first - 42
A company has two internet service providers (ISPs) connected to their ASA. They want to route traffic from the internal network to the primary ISP, but traffic from a specific server (10.10.10.5) should be sent to the secondary ISP for compliance reasons. Which feature should be used to achieve this?
Select an answer first - 43
An engineer is implementing PBR on an FTD device. The route map 'PBR-1' matches traffic from subnet 192.168.10.0/24 and sets the next hop to 10.0.0.1. However, after applying the PBR to the ingress interface, traffic from that subnet is still being forwarded using the routing table. The engineer has verified that the route map is correctly configured and applied. What is the most likely cause of the issue?
Select an answer first - 44
A security team wants to redirect all HTTP traffic from the inside interface to an ASA CX module for advanced inspection. They have already configured the ASA CX module and it is operational. What is the correct way to redirect the traffic?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.