
CCIE Security
Domain 1Objective 11
1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 6)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
20%of the exam
Questions 26–30
- 26
A Cisco ASA has an ACL applied to the outside interface that permits only HTTP and HTTPS inbound to a web server. The web server also needs to be pinged for monitoring. The administrator adds an ACL entry to permit ICMP to the web server, but pings still fail. What is the most likely reason?
Select an answer first - 27
A small business uses a Cisco FTD appliance as its internet gateway. Internal hosts use private IP addresses (192.168.1.0/24) and need to access the internet. The FTD has a single public IP address on its outside interface. The administrator must configure NAT so that all internal hosts can share the public IP for outbound internet access. Which NAT configuration should be used?
Select an answer first - 28
A pair of Cisco ASA firewalls is configured in Active/Standby failover. The failover link is a dedicated GigabitEthernet interface. The primary unit fails, and the standby becomes active. However, the new active unit does not pass traffic. The administrator checks the interface status and sees that the outside interface is down. What is the most likely cause?
Select an answer first - 29
An enterprise runs two Cisco ASA firewalls in an Active/Standby failover pair. The primary unit fails, and the standby takes over. After the failover, users report that they cannot reach the internet. The outside interface IP address is the same on both units, but the default route is not being advertised. What is the most likely cause of the connectivity loss?
Select an answer first - 30
A company wants to connect two branch offices over the internet using Cisco ASA firewalls. Each branch has a static public IP address. The traffic between the branches must be encrypted and should include all IP traffic between the two sites. Which VPN configuration is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.