Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 5Objective 3

5.3 Perform Packet Capture and Analysis Using Wireshark, Tcpdump, SPAN, ERSPAN, and RSPAN CCIE-SECURITY Practice Questions (Page 4)

Part of the 5.0 Advanced Threat Protection and Content Security domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A network engineer needs to monitor traffic from a specific port on a switch. The monitoring device is connected to another port on the same switch. The engineer wants to capture all traffic, including both ingress and egress traffic, from the source port. Which SPAN configuration should be used?

    Select an answer first
  2. 17application · medium

    A company has multiple switches in a single building. Security analysts need to monitor traffic from a server connected to switch A, but the monitoring station is connected to switch C. The switches are connected via a Layer 2 network. Which method should be used to mirror the server's traffic to the monitoring station?

    Select an answer first
  3. 18application · medium

    A security team needs to monitor traffic from a switch in a branch office. The monitoring server is in the corporate data center, and the two locations are connected via a VPN over the internet. The team wants to capture the mirrored traffic using Wireshark on the monitoring server. Which method should they use?

    Select an answer first
  4. 19expert · hard

    A network engineer is troubleshooting a slow application on a Linux server. The engineer suspects that the server is sending excessive traffic to a particular IP address. The engineer needs to capture all traffic to and from that IP address, but only for a limited time, and must avoid capturing unnecessary traffic to keep the capture file small. Which tcpdump command should be used?

    Select an answer first
  5. 20expert · hard

    A security analyst is analyzing a pcap file that contains a large amount of traffic. The analyst needs to identify all TCP sessions that were reset (RST) by the server. Which Wireshark feature should be used to quickly find these sessions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.