
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 5)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 21–25
- 21
A network engineer is configuring DHCP snooping on a switch that also runs DAI. The switch has a mix of DHCP and static IP hosts. The engineer notices that ARP requests from static hosts are being dropped by DAI. What is the most likely cause?
Select an answer first - 22
A network administrator is configuring port security on a switch port that connects to a VoIP phone and a PC. The phone is daisy-chained to the PC. The administrator wants to allow both MAC addresses but also wants to prevent any other device from connecting. Which configuration is correct?
Select an answer first - 23
A network engineer is implementing RA Guard on a switch that also runs DHCPv6 snooping. The engineer wants to ensure that only the legitimate router can send Router Advertisements, but the router uses a link-local address that changes periodically. What is the best way to configure RA Guard?
Select an answer first - 24
A security administrator is using VACLs to filter traffic within a VLAN. The administrator also needs to ensure that BPDUs are not filtered by the VACL. Which configuration should be applied?
Select an answer first - 25
A network administrator is troubleshooting a problem where DHCP snooping is not populating the binding table for some clients. The clients are using static IP addresses. The administrator has enabled DHCP snooping and DAI on the VLAN. What is the most likely cause of the missing bindings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.