
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 6)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 26–30
- 26
A network engineer is securing a switch that connects to a DHCP server and multiple end-user devices. The goal is to prevent rogue DHCP servers and DHCP starvation attacks. The engineer has enabled DHCP snooping globally. What additional configuration is required to achieve the goal?
Select an answer first - 27
A network engineer is configuring DAI on a VLAN that has both DHCP and static hosts. The engineer wants to ensure that ARP requests from static hosts are validated, but also wants to prevent ARP spoofing from DHCP hosts. Which configuration is the most secure and efficient?
Select an answer first - 28
A company wants to restrict each switch port to a single authorized device. The network uses DHCP for IP assignment. The security team wants to prevent MAC spoofing and unauthorized devices from connecting. Which configuration approach best meets these requirements?
Select an answer first - 29
A network administrator is deploying IPv6 on a campus network. The security team is concerned about rogue router advertisements that could redirect traffic. The switches are Cisco Catalyst 3850s. Which feature should be enabled to filter unauthorized IPv6 router advertisements?
Select an answer first - 30
A security administrator needs to block all traffic between two departments that share the same VLAN, except for HTTP and HTTPS traffic to a specific web server. The switch is a Catalyst 4500. Which technology should be used to enforce this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.