
CCIE Security
Domain 2Objective 3
2.3 FlexVPN, DMVPN, and IPsec L2L Tunnels CCIE-SECURITY Practice Questions (Page 6)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
20%of the exam
Questions 26–30
- 26
A DMVPN Phase 2 network is being upgraded to Phase 3 to improve scalability. The engineer has changed the hub configuration to include 'ip nhrp redirect' and the spokes to include 'ip nhrp shortcut'. However, after the upgrade, spokes are still not establishing direct tunnels. What is a possible reason?
Select an answer first - 27
A DMVPN spoke is experiencing high latency when communicating with another spoke. The engineer runs 'show dmvpn' and sees that the NHRP cache has an entry for the remote spoke, but the tunnel is not being used for data traffic. The engineer also sees that the routing table has a route to the remote spoke's subnet via the hub. What is the most likely cause?
Select an answer first - 28
A network engineer is configuring a FlexVPN hub-and-spoke network. The hub has multiple tunnel interfaces for different customers, each with its own IKEv2 profile. The engineer wants to ensure that each customer's traffic is isolated and that the correct IKEv2 profile is selected based on the incoming connection. What should the engineer configure on the hub?
Select an answer first - 29
An IPsec L2L tunnel using IKEv2 is failing to establish. The engineer runs 'debug crypto ikev2' and sees that the IKE_SA_INIT exchange completes, but the IKE_AUTH exchange fails with an authentication error. The tunnel uses pre-shared keys. What is the most likely cause?
Select an answer first - 30
A network engineer is configuring a FlexVPN site-to-site tunnel between two routers. The engineer wants to use IKEv2 with certificate-based authentication and ensure that only specific traffic (e.g., between two LAN subnets) is encrypted. The engineer has already configured the IKEv2 proposal and policy. What is the next required step to complete the FlexVPN configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.