Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 9

1.9 Policies and Rules for Traffic Control on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 2)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
14concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    A company wants to block access to all websites in the 'Social Networking' category, but allow access to all other categories. The FTD is configured with a DNS and URL filtering policy. Which configuration is correct?

    Select an answer first
  2. 7application · medium

    An organization needs to ensure that VoIP traffic gets priority over regular web traffic on their FTD. They have already classified the traffic. Which FTD feature should be used to implement this priority?

    Select an answer first
  3. 8expert · hard

    An ASA has the following ACL applied to the outside interface: 1. permit tcp any host 10.1.1.10 eq 80 2. permit tcp any host 10.1.1.10 eq 443 3. deny ip any any log A user reports they cannot access the web server at 10.1.1.10 on TCP/8080. The administrator checks the logs and sees that the traffic is being denied by the implicit deny rule, not the explicit deny. What is the most likely reason for this?

    Select an answer first
  4. 9expert · hard

    An ASA is configured with an MPF policy that inspects HTTP traffic. A new requirement is to also inspect HTTPS traffic, but only for a specific server (10.1.1.20). The administrator creates a new class that matches traffic to 10.1.1.20 on TCP/443 and applies the 'inspect https' action. However, the HTTPS traffic is not being inspected. What is the most likely cause?

    Select an answer first
  5. 10expert · hard

    An FTD administrator is troubleshooting a connectivity issue. A user reports that they cannot access a specific internal server (10.1.1.50) from the internet. The administrator has verified that the access control policy has a rule that permits this traffic. However, the traffic is still being blocked. What is the next most likely place to check?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.