Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 11

1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 5)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts
20%of the exam

Questions 21–25

  1. 21expert · medium

    A site-to-site VPN between two Cisco ASAs is configured with IPsec. The tunnel is up, but traffic from one site to the other is not passing. The administrator checks the crypto map and sees that the ACL matches the correct source and destination. What is the most likely cause?

    Select an answer first
  2. 22expert · medium

    A Cisco FTD is experiencing intermittent connectivity issues. The administrator uses the capture command to capture traffic on the inside and outside interfaces. The capture shows packets entering the inside interface but not leaving the outside interface. What is the most likely cause?

    Select an answer first
  3. 23expert · medium

    An organization is deploying a pair of Cisco FTDs in a cluster for high availability. The cluster will use two physical interfaces for data traffic: one for inside and one for outside. The administrator wants to ensure that if one interface fails, the cluster continues to forward traffic. What is the best configuration?

    Select an answer first
  4. 24expert · medium

    A Cisco ASA is running OSPF with a neighboring router. The OSPF adjacency is up, but routes from the neighbor are not appearing in the ASA's routing table. The administrator verifies that the OSPF configuration is correct. What is the most likely cause?

    Select an answer first
  5. 25expert · medium

    A Cisco FTD is configured with a site-to-site VPN to a partner. The VPN tunnel is up, but users on the internal network cannot reach the partner's network. The administrator checks the NAT configuration and finds that the internal network is being translated to a different IP when going through the VPN. What is the best solution?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.