Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 11

1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 7)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts
20%of the exam

Questions 31–35

  1. 31application · medium

    Users on a protected network cannot reach a public web server. The Cisco ASA has an ACL that permits HTTP traffic from the inside to the outside. The administrator runs the packet tracer tool and sees that the packet is dropped at the ACL stage. What is the most likely cause?

    Select an answer first
  2. 32application · medium

    A Cisco FTD is deployed as a router between two networks: 10.1.1.0/24 and 10.2.2.0/24. The FTD has interfaces in both subnets. The administrator wants to enable communication between the two networks without using dynamic routing. What is the simplest configuration?

    Select an answer first
  3. 33application · medium

    A company runs a web server in a DMZ behind a Cisco ASA. The web server has a private IP address (192.168.2.10) and needs to be accessible from the internet via a public IP (203.0.113.10). The administrator must configure NAT so that internet users can reach the web server. Which NAT configuration is required?

    Select an answer first
  4. 34application · medium

    A Cisco ASA has an ACL that permits only HTTP and HTTPS traffic from the inside to the outside. Users report that they can browse websites but cannot ping external IP addresses. The administrator wants to allow ICMP echo requests for troubleshooting. What should be done?

    Select an answer first
  5. 35application · medium

    An organization is deploying two Cisco FTD appliances in a cluster to provide high availability and increased throughput. The cluster will be placed between the core switch and the internet router. What is a key requirement for the cluster interfaces?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.