
CCIE Security
Domain 2Objective 3
2.3 FlexVPN, DMVPN, and IPsec L2L Tunnels CCIE-SECURITY Practice Questions (Page 8)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
20%of the exam
Questions 36–37
- 36
An engineer is configuring a traditional IPsec L2L tunnel using IKEv2 and crypto maps. The engineer has created the IKEv2 proposal, policy, and keyring. What is the next step to complete the configuration?
Select an answer first - 37
An IPsec L2L tunnel is not passing traffic. The engineer runs 'show crypto ipsec sa' and sees that the IPsec SAs are active, but the packet count is zero. What is the most likely cause?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.