
CCIE Security
Domain 4Objective 15
4.15 pxGrid Integration Between Security Devices Cisco WSA, Cisco ISE, and Cisco FMC CCIE-SECURITY Practice Questions (Page 7)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
25%of the exam
Questions 31–35
- 31
A network engineer has configured pxGrid between Cisco ISE and Cisco WSA. The integration is not working; WSA is not receiving endpoint identity updates. The engineer has verified that both devices are reachable and certificates are trusted. What should the engineer check next?
Select an answer first - 32
A large enterprise is deploying pxGrid across multiple sites. They have two ISE deployments (primary and secondary) and want to ensure high availability for pxGrid. The requirement is that if the primary ISE fails, WSA and FMC should continue to receive updates without manual intervention. What is the best approach?
Select an answer first - 33
A security architect is designing a new pxGrid deployment for a multi-vendor environment. The team needs to ensure that all security devices can share real-time context without a single point of failure. The architect decides to deploy multiple pxGrid controllers. Which role must these controllers assume in the pxGrid architecture to support this design?
Select an answer first - 34
A company has integrated WSA and ISE via pxGrid. They want to enforce different web policies based on user identity and device posture. Currently, WSA is receiving identity information but not posture. The ISE policy is set to evaluate posture, but WSA still does not see posture status. What is the most likely reason?
Select an answer first - 35
A security team has integrated ISE and FMC via pxGrid. They want to automatically block an endpoint when FMC detects a threat. The integration is working, but the blocking action is not being applied. The team has verified that FMC is publishing threat events and ISE is subscribed. What should they check next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.