
CCIE Security
Domain 4Objective 14
4.14 Identity Mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 3)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
25%of the exam
Questions 11–15
- 11
What is a common method for Cisco WSA to obtain user identity information?
Select an answer first - 12
On Cisco FTD, what is required to enable identity mapping for user-aware access control?
Select an answer first - 13
A company runs a Cisco ASA 5506-X as its internet gateway. They need to enforce different VPN access policies based on the Active Directory group membership of remote users. The ASA is already joined to the AD domain and can resolve user identities. Which configuration step is essential to enable user-based access control on the ASA?
Select an answer first - 14
A network architect is choosing between Cisco ASA and Cisco WSA for a new branch office. The requirement is to enforce user-based web filtering and also provide VPN access. Which statement correctly compares the identity mapping capabilities of these two devices?
Select an answer first - 15
A company has deployed Cisco FTD in a high-availability pair. They want to enforce user-based access control using Active Directory. The FTDs are managed by FMC. What is the best practice for configuring identity mapping in this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.