
CCIE Security
Domain 1Objective 11
1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 8)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
20%of the exam
Questions 36–40
- 36
A company is deploying a new Cisco FTD appliance as the perimeter firewall. The inside network uses VLAN 10 (192.168.10.0/24) and VLAN 20 (192.168.20.0/24). The FTD has one physical interface connected to the inside switch. The network team wants to route between the two VLANs through the FTD and then to the upstream router. What is the most efficient way to configure the FTD to achieve this connectivity?
Select an answer first - 37
A company is setting up two Cisco ASA firewalls in an Active/Standby failover pair. They have a dedicated failover link and also use the data interfaces for failover communication. The administrator wants to ensure that if the active unit fails, the standby unit takes over the same IP addresses and maintains stateful connections. What is required for stateful failover?
Select an answer first - 38
A remote worker needs to connect to the corporate network using a VPN client. The company uses a Cisco ASA with AnyConnect. The user can connect to the VPN but cannot access any internal resources. The administrator has verified that the VPN tunnel is up and the user has been assigned an IP address. What is the most likely cause?
Select an answer first - 39
A network administrator is troubleshooting a connectivity issue on a Cisco FTD. Users on the inside network can access the internet, but they cannot access a specific external server. The administrator has verified that the NAT and routing are correct. What is the next best step to identify the problem?
Select an answer first - 40
A large enterprise is deploying a pair of Cisco FTDs in a cluster. They have two upstream ISPs for redundancy. The FTDs will run BGP to the ISPs and OSPF to the internal network. The internal network has multiple VLANs, and the FTDs will use subinterfaces for each VLAN. The security policy requires that all traffic from the internal network to the internet be inspected, but traffic between internal VLANs should be allowed without inspection. What is the best way to configure the FTDs to meet these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.