
CCIE Security
Domain 3Objective 4
3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 7)
Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
15%of the exam
Questions 31–35
- 31
A network engineer is implementing IPv6 First Hop Security features on a switch. The goal is to track IP-to-MAC bindings for IPv6 hosts to support RA Guard and DHCPv6 Guard. Which feature should be enabled to build this binding table?
Select an answer first - 32
A network administrator is securing a switch that connects to a core switch and several end-user devices. The administrator wants to prevent any end-user device from becoming the STP root bridge. Which configuration should be applied?
Select an answer first - 33
A network administrator is configuring a switch to prevent DHCP starvation attacks. The switch has DHCP snooping enabled globally and on VLAN 10. The administrator wants to limit the rate of DHCP requests on each access port. Which configuration should be applied?
Select an answer first - 34
A network admin is troubleshooting intermittent ARP failures in a campus LAN. Users report that some devices cannot reach the default gateway, and the switch logs show frequent ARP cache updates. The admin suspects ARP spoofing. DHCP snooping is already enabled globally. What should the admin configure to validate ARP packets and prevent spoofing?
Select an answer first - 35
An admin is configuring DAI on a VLAN where some devices use static IP addresses. The DHCP snooping binding table does not contain entries for these static devices. What should the admin do to ensure DAI does not drop ARP packets from these devices?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.