Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 14

4.14 Identity Mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 5)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
25%of the exam

Questions 21–25

  1. 21expert · hard

    A company has deployed Cisco FTD with identity mapping using Active Directory. They are experiencing performance issues on the FTD when many users are active. The security team suspects that the identity mapping is causing excessive LDAP queries. What is the best way to reduce the LDAP query load while maintaining accurate identity mapping?

    Select an answer first
  2. 22expert · hard

    A security architect is designing a solution for a multi-site company. They need to enforce user-based web filtering and firewall policies. They have a central Active Directory and want to minimize latency for identity lookups. Which design is most effective?

    Select an answer first
  3. 23application · medium

    A university uses Cisco ISE to enforce network access control. They want to allow faculty members to access a research database only when they are on the campus network, while students are blocked. The ISE is integrated with Active Directory. Which ISE feature should be used to achieve this user-based access control?

    Select an answer first
  4. 24application · medium

    A company uses Cisco WSA to filter web traffic. They want to block social media sites for employees in the 'Marketing' AD group but allow them for the 'Social Media Team' group. The WSA is already integrated with Active Directory. What is the most efficient way to apply these user-based policies?

    Select an answer first
  5. 25application · medium

    A company is migrating from Cisco ASA to Cisco Firepower Threat Defense (FTD) for their perimeter firewall. They need to enforce user-based access control based on Active Directory groups. The FTD is managed by FMC. What is the required configuration on FMC to enable identity-based policies?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.