Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 14

4.14 Identity Mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD CCIE-SECURITY Practice Questions (Page 9)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
25%of the exam

Questions 41–45

  1. 41application · medium

    An enterprise is deploying Cisco ISE to provide identity mapping for multiple network devices, including switches, wireless controllers, and firewalls. The goal is to have a single source of truth for user identity and to enforce consistent access policies. Which ISE feature should be used to distribute identity information to these devices?

    Select an answer first
  2. 42expert · hard · select all that apply

    A security architect is comparing identity mapping implementations across Cisco ASA, ISE, WSA, and FTD. Which of the following statements are correct? (Select all that apply.)

    Select an answer first
  3. 43application · medium

    A company uses Cisco WSA to enforce web filtering policies. They want to apply different policies based on the user's Active Directory group membership, but they do not have a separate identity service. The WSA should directly integrate with Active Directory to map users to IP addresses. Which configuration is required on the WSA?

    Select an answer first
  4. 44application · medium

    A network administrator is configuring a Cisco Firepower Threat Defense (FTD) device for user-aware access control. The FTD is managed by Firepower Management Center (FMC). The organization uses Active Directory for user identity. Which method should the administrator use to enable identity mapping on the FTD?

    Select an answer first
  5. 45expert · hard

    A large enterprise has a mixed environment with Cisco ASA and Cisco FTD devices. They are planning to implement identity mapping for user-based access control. The ASA devices are older and do not support the same identity features as FTD. The organization wants a consistent identity mapping approach across all devices without major hardware upgrades. Which strategy should they adopt?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.