Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 9

1.9 Policies and Rules for Traffic Control on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 3)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
14concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    An FTD is configured to decrypt and inspect HTTPS traffic. After enabling this, the administrator notices that some users are unable to access certain websites that use certificate pinning. The access control policy is set to 'Allow' for these sites. What is the most likely cause of the issue?

    Select an answer first
  2. 12expert · hard

    An FTD administrator is configuring URL filtering. They have created a rule that blocks the 'Social Networking' category. However, users are still able to access Facebook. The administrator has verified that the rule is enabled and placed at the top of the access control policy. What is the most likely reason for this?

    Select an answer first
  3. 13expert · hard

    An FTD administrator is configuring QoS to prioritize VoIP traffic. They have created a QoS policy that assigns a higher priority to VoIP traffic. However, they notice that VoIP traffic is still experiencing latency. What is the most likely cause?

    Select an answer first
  4. 14application · medium

    An administrator needs to create an ACL on an ASA to allow traffic from the 192.168.10.0/24 and 192.168.20.0/24 networks to reach a server at 10.10.10.5 on ports TCP/80 and TCP/443. The administrator wants to minimize the number of ACEs and simplify future changes. Which approach is the most efficient?

    Select an answer first
  5. 15application · medium

    A company wants to allow remote employees to access the corporate network via VPN only during business hours (Monday to Friday, 8:00 AM to 6:00 PM). The ASA ACL currently has a permit statement for VPN traffic. What is the correct way to enforce this time restriction?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.