
CCIE Security
Domain 2Objective 6
2.6 Microsegmentation with Cisco TrustSec Using SFT and SXP CCIE-SECURITY Practice Questions (Page 7)
Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
11concepts
20%of the exam
Questions 31–35
- 31
A network engineer is configuring SXP between two switches. The engineer wants to ensure that the SXP session is resilient to link flaps and that bindings are not lost. Which configuration should be applied?
Select an answer first - 32
A university campus has a mix of Cisco switches that support SFT and older distribution switches that do not. The security team wants to enforce TrustSec policies for student, faculty, and guest traffic. They plan to use SXP to propagate SGT bindings from the access layer to the distribution layer. Which SXP connection mode should be configured on the distribution switch to receive bindings from multiple access switches?
Select an answer first - 33
A healthcare organization is implementing TrustSec to separate patient records, billing, and research departments. They have defined SGTs for each department and created SGACLs to permit or deny traffic between them. The network includes both SFT-capable and non-SFT-capable switches. Which statement correctly describes how SGTs and SGACLs are enforced in this mixed environment?
Select an answer first - 34
A large enterprise is deploying SFT on its campus access switches to enforce microsegmentation between IoT devices and corporate PCs. The network team wants to ensure that SFT operates correctly at the data plane. Which action is required for SFT to forward traffic with embedded SGTs and enforce SGACLs?
Select an answer first - 35
A retail chain has legacy switches that do not support SFT. They are deploying TrustSec to enforce policies between point-of-sale (POS) systems and back-office servers. The network engineer needs to propagate SGT bindings from the access switches (which are SFT-capable) to the legacy distribution switches. Which SXP configuration is appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.