
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 4)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 16–20
- 16
A network administrator is implementing DAI on a VLAN that uses static IP addresses for servers and DHCP for clients. The administrator wants to ensure that ARP requests for the static servers are validated. What is the best approach?
Select an answer first - 17
A company has a policy that each switch port should allow only one MAC address, and if a different MAC is seen, the port should be shut down permanently until manually re-enabled. Which port security configuration meets this requirement?
Select an answer first - 18
A network engineer is deploying IPv6 on a segment with multiple access switches. The engineer wants to ensure that only the legitimate router can send Router Advertisements. Which feature should be enabled on the access ports?
Select an answer first - 19
A security administrator needs to block all traffic between two hosts in the same VLAN, but allow them to communicate with a server in a different VLAN. The switch is a Catalyst 6500 with a Supervisor Engine 720. The administrator has configured a VACL to deny traffic between the hosts. However, the hosts can still ping each other. What is the most likely cause?
Select an answer first - 20
A network administrator is troubleshooting an STP issue where a switch port keeps going into errdisable state. The port is connected to a device that is sending BPDUs. The administrator wants to allow the port to recover automatically after 5 minutes. Which configuration should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.