
CCIE Security
Domain 5Objective 3
5.3 Perform Packet Capture and Analysis Using Wireshark, Tcpdump, SPAN, ERSPAN, and RSPAN CCIE-SECURITY Practice Questions (Page 3)
Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
20%of the exam
Questions 11–15
- 11
In an RSPAN configuration, what is the role of the RSPAN VLAN?
Select an answer first - 12
What encapsulation protocol does ERSPAN use to transport mirrored traffic over an IP network?
Select an answer first - 13
A security analyst needs to capture traffic on a Linux-based firewall to investigate a suspected malware beacon. The analyst must capture only HTTPS traffic to a specific external IP and save the capture to a file for later analysis in Wireshark. The firewall has no GUI. Which approach should the analyst use?
Select an answer first - 14
A network administrator needs to capture traffic on a Linux router to troubleshoot a connectivity issue. The administrator wants to capture only ICMP echo requests and replies to and from the router's external interface. Which tcpdump command should be used?
Select an answer first - 15
A security analyst has captured a pcap file and needs to identify all packets that contain a specific string in the payload. The analyst is using Wireshark. Which of the following methods can be used to find these packets? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.