
CCIE Security
Domain 4Objective 14
4.14 Identity Mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 4)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
25%of the exam
Questions 16–20
- 16
A company uses Cisco WSA to control web access. They have a requirement to block file-sharing sites for all users except the 'Engineering' AD group. The WSA is already integrated with AD. What is the most effective way to implement this?
Select an answer first - 17
A company is consolidating its security infrastructure. They currently have a Cisco ASA running as a firewall and VPN concentrator, and they are planning to replace it with Cisco FTD. They also use Cisco ISE for network access control. The security team wants to maintain user-based access control for both VPN and firewall traffic. They have a limited budget and want to minimize changes to their existing ISE deployment. Which approach best meets these requirements?
Select an answer first - 18
A Cisco ASA is configured with identity mapping using Active Directory. The security team notices that some users are not being mapped to the correct AD groups, causing access issues. They have verified that the ASA can reach the AD server and authentication works. What is the most likely cause of the incorrect group mapping?
Select an answer first - 19
A company uses Cisco ISE for network access control and has a Cisco FTD firewall. They want to enforce user-based policies on the FTD based on AD groups. They have integrated ISE with FMC via pxGrid. However, the FTD is not receiving identity updates for some users. The ISE shows the users are authenticated and assigned to the correct identity group. What is the most likely issue?
Select an answer first - 20
A Cisco WSA is configured to use Active Directory for authentication. The security team wants to apply different web filtering policies based on AD group membership. They have created the policies, but some users are being matched to the wrong policy. They have verified that the users are in the correct AD groups. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.