
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 2)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 6–10
- 6
Which of the following can be used in a VACL to filter traffic?
Select an answer first - 7
Which database does Dynamic ARP Inspection (DAI) rely on to validate ARP packets?
Select an answer first - 8
What is the primary purpose of IP Device Tracking (IPDT) on a switch?
Select an answer first - 9
Which security feature is directly supported by IP Device Tracking (IPDT)?
Select an answer first - 10
Which STP security mechanism is used to protect the root bridge from being taken over by an unauthorized switch?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.