Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 3Objective 2

3.2 Management Plane Protection Techniques CCIE-SECURITY Practice Questions (Page 1)

Part of the 3.0 Security Infrastructure domain, which accounts for 15% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)

16questions here
4free pages
7concepts
15%of the exam

Questions 1–5

  1. 1application · medium

    A network engineer is configuring a new Cisco router that will be deployed at a branch office. The router's control plane has been experiencing high CPU utilization due to excessive ICMP and SNMP traffic. The engineer wants to protect the control plane CPU while still allowing legitimate management traffic. Which configuration approach should the engineer implement?

    Select an answer first
  2. 2application · medium

    A network administrator is concerned about a potential memory exhaustion attack on a core switch. The administrator wants to configure the switch to automatically take action when memory usage reaches a critical level. Which configuration should be implemented?

    Select an answer first
  3. 3application · medium

    A network engineer is configuring a router that will be managed remotely. The engineer wants to ensure that memory usage is monitored and that the router sends alerts when memory usage is high. Which configuration should be applied?

    Select an answer first
  4. 4application · medium

    A company is implementing a new security policy that requires all network devices to use role-based access control (RBAC) to limit the commands that administrators can execute. The policy also requires that all management access be encrypted. Which configuration should be applied to meet these requirements?

    Select an answer first
  5. 5expert · medium

    A large enterprise is deploying a new core router. The security team has identified that the router is vulnerable to control plane DoS attacks. The team wants to implement a solution that protects the control plane CPU while ensuring that legitimate management traffic (SSH, SNMP) and routing protocols (OSPF, BGP) are not dropped. The solution must also restrict management access to only the network operations center (NOC) IP addresses. Which configuration approach should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.