
CCIE Security
Domain 4Objective 14
4.14 Identity Mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 6)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
25%of the exam
Questions 26–30
- 26
A network engineer is comparing identity mapping capabilities between Cisco ASA and Cisco FTD for a new deployment. The company requires integration with Cisco ISE for centralized policy management. Which statement accurately describes a key difference between ASA and FTD in this context?
Select an answer first - 27
A security administrator is designing a solution to enforce user-based web filtering and network access control across multiple devices. They want to use a single identity source to avoid duplicate user databases. Which approach best leverages identity mapping to achieve this?
Select an answer first - 28
A company uses Cisco WSA for web security. They have a mix of authenticated users (via AD) and unauthenticated guest users. They want to apply a stricter web filter for guests. What is the best way to achieve this using identity mapping?
Select an answer first - 29
A Cisco ASA is used as a VPN concentrator. The security team wants to restrict access to internal servers based on the user's AD group. They have configured AAA authentication against AD. What additional configuration is needed on the ASA to use AD group membership in access rules?
Select an answer first - 30
A company uses Cisco ISE to enforce access control on their wired network. They also have a Cisco FTD firewall. They want the FTD to use ISE for identity mapping so that firewall rules can be user-based. Which integration method is appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.