
CCIE Security
Domain 5Objective 8
5.8 HTTP Decryption and Inspection on Cisco FTD, Cisco WSA, and Cisco Umbrella CCIE-SECURITY Practice Questions (Page 6)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
20%of the exam
Questions 26–30
- 26
An organization is deploying Cisco FTD with HTTPS decryption. They want to ensure that decrypted traffic is inspected by the intrusion prevention system (IPS) and malware detection. They also want to minimize performance impact. What is the best way to configure this?
Select an answer first - 27
A financial services company is implementing HTTPS inspection on Cisco WSA. They must comply with PCI DSS and avoid decrypting traffic to banking and payment sites. They also want to decrypt other web traffic for security. What is the best way to handle this?
Select an answer first - 28
A company is using Cisco FTD for HTTPS decryption. They have a custom internal CA and want to decrypt traffic to internal servers. They have installed the internal CA certificate on the FTD. However, users still see certificate errors when accessing internal HTTPS sites. What is the likely issue?
Select an answer first - 29
A large enterprise is planning to deploy HTTPS decryption on Cisco WSA for 10,000 users. They are concerned about the performance impact on the WSA. What is the best practice to ensure scalability?
Select an answer first - 30
A company is deploying Cisco FTD with SSL decryption. Users report that some internal applications fail with certificate errors. The internal CA used for re-signing decrypted certificates is not trusted by the application servers. What should you do to resolve this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.