
CCIE Security
Domain 1Objective 11
1.11 Network Connectivity Through Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 9)
Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
20%of the exam
Questions 41–45
- 41
A company has a Cisco ASA with three interfaces: inside (192.168.1.0/24), outside (public IP 203.0.113.1), and DMZ (10.0.0.0/24). They want to allow internal users to access the internet and also host a web server in the DMZ (10.0.0.5) that must be reachable from the internet via the public IP 203.0.113.1. Additionally, they want to allow internal users to access the DMZ server using its private IP. The security policy requires that all traffic from the internet to the DMZ be restricted to HTTPS only. What is the correct NAT and ACL configuration?
Select an answer first - 42
A company is deploying two Cisco ASA firewalls in an Active/Standby failover pair. They have a dedicated failover link and also use the data interfaces for failover communication. The administrator wants to ensure that if the active unit fails, the standby unit takes over the same IP addresses and maintains stateful connections. What is required for stateful failover?
Select an answer first - 43
A branch office uses a Cisco ASA with a single public IP address on the outside interface. Internal users on the 192.168.1.0/24 network need to access the internet. The security policy requires that all outbound traffic be translated to the public IP, but the ASA must also allow inbound traffic to a public web server located inside the DMZ (10.0.0.5). Which configuration approach satisfies both requirements?
Select an answer first - 44
An organization is deploying two Cisco ASA firewalls in an Active/Standby failover pair. They want to ensure that if the active unit fails, the standby unit takes over with minimal disruption. The network uses a single inside and outside interface, and the firewalls are connected via a dedicated failover link. What is the minimum configuration required to enable failover?
Select an answer first - 45
A company wants to connect its headquarters and a remote branch office over the internet using a site-to-site VPN. The headquarters uses a Cisco FTD, and the branch uses a Cisco ASA. The internal networks are 10.1.0.0/16 and 10.2.0.0/16 respectively. The security team wants to ensure that only traffic between these two networks is allowed through the VPN, and that all other traffic is blocked. What should be configured on both devices?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.