Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 4

3.4 Layer 2 Security Techniques CCIE-SECURITY Practice Questions (Page 8)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
7concepts
15%of the exam

Questions 36–40

  1. 36application · medium

    A network admin wants to ensure that only a specific laptop is allowed on a particular switch port. The laptop's MAC address is known. The admin also wants to protect the STP topology from unauthorized switches. What should be configured on the port?

    Select an answer first
  2. 37application · medium

    An organization is concerned about IPv6 rogue router advertisements on their network. They have already implemented RA Guard on access ports. However, they also want to filter IPv6 traffic between two segments within the same VLAN. What additional feature should be used?

    Select an answer first
  3. 38expert · hard

    A switch has DHCP snooping enabled, and DAI is configured on VLAN 20. The admin wants to enable IP source guard on access ports to prevent IP spoofing. However, some devices on the network use static IP addresses and are not in the DHCP snooping binding table. The admin has enabled IPDT to track these devices. Which additional configuration is required to ensure IP source guard does not block legitimate static IP traffic?

    Select an answer first
  4. 39expert · hard

    A network admin is securing a switch that connects to a core switch via a trunk port. The admin wants to prevent any unauthorized switch from becoming the root bridge, but also wants to allow the core switch to remain the root. Additionally, the admin wants to prevent DHCP spoofing on access ports. Which configuration is correct?

    Select an answer first
  5. 40expert · hard

    A security policy requires that all ARP traffic between two VLANs be blocked, but DHCP traffic must be allowed. The switch is already running DHCP snooping and DAI. What is the best way to enforce this policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.