
CCIE Security
Domain 1Objective 11
1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 10)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
20%of the exam
Questions 46–50
- 46
A network administrator is troubleshooting a connectivity issue on a Cisco ASA. Users on the inside network (192.168.1.0/24) cannot reach the internet. The administrator has verified that the default route is configured and the NAT policy is in place. However, traffic is still not passing. What is the next best step to isolate the problem?
Select an answer first - 47
A data center is deploying a pair of Cisco FTDs in a cluster for high availability. Each FTD has four 10-Gigabit Ethernet interfaces that will be used for data traffic. The cluster needs to provide a total of 40 Gbps throughput. To achieve this, the interfaces on each FTD should be combined into a single logical link. What is the correct way to configure this on FTD?
Select an answer first - 48
A Cisco ASA is configured with OSPF as the routing protocol on the inside interface. The outside interface uses a static default route to the ISP. The administrator notices that OSPF routes are not being installed in the routing table. What is a likely cause?
Select an answer first - 49
A company has a Cisco FTD with three interfaces: inside (192.168.1.0/24), outside (public IP), and DMZ (10.0.0.0/24). They want to allow internal users to access the internet and also allow external users to access a web server in the DMZ. The web server has a private IP (10.0.0.5) and must be reachable via the public IP. What NAT configuration is required?
Select an answer first - 50
A Cisco ASA is configured with an access-list that permits HTTP traffic from the inside network to the outside network. However, users are unable to browse the internet. The administrator checks the NAT configuration and finds that PAT is configured. What is the most likely reason for the failure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCIE-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.