Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 1Objective 9

1.9 Policies and Rules for Traffic Control on Cisco ASA and Cisco FTD CCIE-SECURITY Practice Questions (Page 4)

Part of the 1.0 Perimeter Security and Intrusion Prevention domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
14concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    An administrator needs to apply different inspection policies to traffic based on the destination port. For example, HTTP traffic to a specific server should have deeper inspection than HTTP traffic to other servers. Which ASA feature is best suited for this requirement?

    Select an answer first
  2. 17application · medium

    A security team needs to ensure that all FTP traffic passing through the ASA is inspected to prevent common FTP-based attacks. They also want to log any FTP traffic that is denied. Which configuration is required?

    Select an answer first
  3. 18application · medium

    An FTD administrator is creating an access control policy to allow internal users to access the internet, but block access to a specific social media site. The administrator has already created a URL object for the site. What is the correct order of rules in the access control policy?

    Select an answer first
  4. 19application · medium

    An FTD administrator wants to drop all traffic from a known malicious IP address before it is processed by the access control policy, to reduce CPU load. Which feature should be used?

    Select an answer first
  5. 20application · medium

    An organization wants to detect and block known exploit attempts against its web servers. The FTD is already in place, and the access control policy allows traffic to the web servers. What additional configuration is required to enable this protection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.