
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 11)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 51–53
- 51
A network admin is implementing DHCP snooping and IP source guard on a switch. They notice that IP source guard is not working correctly for static IP hosts. What additional feature should be enabled to allow IP source guard to track static IP-to-MAC bindings?
Select an answer first - 52
A network admin wants to prevent a rogue switch from becoming the root bridge in the STP topology. The admin also wants to ensure that if a BPDU is received on an access port, the port is shut down. Which combination of features should be enabled?
Select an answer first - 53
A company is experiencing DHCP starvation attacks where an attacker exhausts the IP address pool. They have enabled DHCP snooping, but the attack continues. What additional measure should be taken to mitigate the attack?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.