Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 11

1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 4)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts
20%of the exam

Questions 16–20

  1. 16foundation · easy

    What is the function of an access control list (ACL) on a Cisco ASA or FTD?

    Select an answer first
  2. 17application · medium

    A company is deploying a pair of Cisco ASA firewalls in a DMZ to segment a web server farm. The network team has allocated a single physical interface on each ASA for the DMZ segment, but the web servers are spread across two VLANs (VLAN 10 and VLAN 20) that must be isolated. The ASAs must route between these VLANs and also to the inside network. What configuration should be applied to the ASA interfaces to meet these requirements?

    Select an answer first
  3. 18application · medium

    A remote worker needs to securely access the corporate network from a hotel Wi-Fi. The company uses Cisco FTD with AnyConnect. The user connects successfully but cannot access internal resources. The administrator checks the VPN session and sees that the user has an IP address from the VPN pool. What is the most likely cause?

    Select an answer first
  4. 19expert · medium

    A Cisco FTD is configured with dynamic PAT for outbound internet access. Users report that some websites fail to load intermittently. The administrator notices that the PAT pool is exhausted. What is the best solution to resolve this issue?

    Select an answer first
  5. 20expert · medium

    Two Cisco ASA firewalls are configured in Active/Standby failover. The primary unit has a static route to an internal network via a router. The standby unit does not have this route. After a failover, traffic to that internal network fails. What is the best way to prevent this in the future?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.