
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 10)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 46–50
- 46
A network admin is configuring DAI on a VLAN that has both DHCP and static IP devices. The admin has enabled DHCP snooping and created an ARP ACL for static hosts. However, the admin also wants to ensure that ARP packets from unknown devices are dropped, but DHCP traffic is still allowed. What should be done?
Select an answer first - 47
A network admin wants to protect the Layer 2 topology from unauthorized switches being connected to access ports. The admin also wants to limit the number of MAC addresses allowed on those ports. Which two features should be enabled on the access ports?
Select an answer first - 48
A company wants to prevent employees from plugging personal devices into the network. They have enabled port security on access ports with a maximum of 2 MAC addresses. However, they also want to ensure that if a violation occurs, the port is automatically disabled and requires manual intervention. Which violation mode should be configured?
Select an answer first - 49
An organization is deploying IPv6 and wants to prevent rogue router advertisements from unauthorized devices on the access layer. They also want to ensure that legitimate router advertisements from the core are not blocked. What should be configured on the access switches?
Select an answer first - 50
A security policy requires that all traffic between two departments in the same VLAN be blocked, except for HTTP/HTTPS. The admin has already implemented DAI and DHCP snooping. What should be used to enforce this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.